I have a firewall log search returning two different types of events but I'm trying to capture the source ip address from both. The events look like:
Deny inbound icmp src inside:172.22.15.90 ...
Inbound TCP connection denied from 172.22.15.90/53340 ...
The Field Extraction tool comes up with one or the other:
(?i) src inside:(?P [^/ ]+)
(?i) denied from (?P [^/ ]+)
Is there a way to combine the two regex statements into a single which will return a field called src_ip_inside for either event?
... View more