Hello,
I am trying to extract fields from a feed that I have, but the automated field extractor is not working for me though. I want to tag the IP address at the very end of every line and call it 'src_ip'. However the automated tool picks up the two CIDr notations every time as well as the IP address at the end of the line.
I am looking for Regex that will only pickup the IP address at the end of each line, and NOT the CIDr notations.
20150404 00:12 http://www.yahoo.com domain\user faddr=192.168.1.0/24 gaddr=192.168.1.0/24 192.168.1.68
20150404 00:12 http://www.yahoo.com domain\user faddr=192.168.1.0/24 gaddr=192.168.1.0/24 192.168.1.21
Would really appreciate somebody to provide me with the Regex it would be much appreciated.
Many thanks
Here you go:
^([^\s]+\s+){6}(?P<src_ip>\d+\.\d+\.\d+\.\d+)