See How do I find all unique IP addresses in a file?
Basically you can find ip interactivly using a search command:
| rex max_match=100 "\b(?<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\b"
Or you can setup an automatic field extraction in your props.conf
and transforms.conf
files.
props.conf:
[my_source_type]
REPORT-ips = all_the_ips
transforms.conf:
[all_the_ips]
REGEX = \b(?<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\b
MV_ADD = True
See How do I find all unique IP addresses in a file?
Basically you can find ip interactivly using a search command:
| rex max_match=100 "\b(?<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\b"
Or you can setup an automatic field extraction in your props.conf
and transforms.conf
files.
props.conf:
[my_source_type]
REPORT-ips = all_the_ips
transforms.conf:
[all_the_ips]
REGEX = \b(?<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\b
MV_ADD = True