Splunk Search

Regex help!!!

splunker9999
Path Finder

Hi,

Can someone please help with formatting IP address or FQDN,we nee to remove [ ] in the below.

These below details are available in field name "Indicator_Value"

221[.]138[.]128[.]116
www[.]cderlearn[.]com

Thanks

Tags (1)
0 Karma

gokadroid
Motivator

Try this using mode=sed

your query to return events
| rex field=Indicator_Value mode=sed "s/\[//g
s/\]//g"

Please ensure to keep the string "s/\[//g and s/\]//g" split over two lines exactly how it appears in the query. Take care of the " (double quotes) to be same as it appears in the query.

0 Karma

twinspop
Influencer
... | eval newfield=replace(Indicator_Value,"[\[\]]","")
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...