Splunk Search

Regex help!!!

splunker9999
Path Finder

Hi,

Can someone please help with formatting IP address or FQDN,we nee to remove [ ] in the below.

These below details are available in field name "Indicator_Value"

221[.]138[.]128[.]116
www[.]cderlearn[.]com

Thanks

Tags (1)
0 Karma

gokadroid
Motivator

Try this using mode=sed

your query to return events
| rex field=Indicator_Value mode=sed "s/\[//g
s/\]//g"

Please ensure to keep the string "s/\[//g and s/\]//g" split over two lines exactly how it appears in the query. Take care of the " (double quotes) to be same as it appears in the query.

0 Karma

twinspop
Influencer
... | eval newfield=replace(Indicator_Value,"[\[\]]","")
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...