Hi All,
I want to count how many IP access to my Web Server in a period ?
I really don't know
Please show me sample : regex and etc ...
Thanks
goldarrow
Not sure your question really falls into the area of regex. I'm going to make some assumptions:
Assuming both of those are true, then what you want should be a simple search in Splunk, something like:
sourcetype=access_combined | timechart dc(src_ip)
If my assumptions are off, you're going to have to clarify some so we can tell where you are.