| metadata type=hosts | regex host!="^(?:\d{1,3}\.){3}\d{1,3}"
Use regex
to find all host
that doesn't follow the IPv4 address like 223.34.2.99
.
More info about regex
: http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/regex
| metadata type=hosts | regex host!="^(?:\d{1,3}\.){3}\d{1,3}"
Use regex
to find all host
that doesn't follow the IPv4 address like 223.34.2.99
.
More info about regex
: http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/regex
Thanks Much @skawasaki_splunk I gave you 5 points but this was too easy for you. Thanks again for the help.