Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Field Extraction issue

$
0
0
HI Experts, i am able to exact 4th and 5th fields from below log but i am able to exact get the value if the 4th or 5th filed is HOSTNAME but if it is IPaddress then i am not able retrieve.here is the sample log tcp 0 0 10.40.88.178:7171 10.40.88.175:50326 ESTABLISHED tcp 0 0 12b8-splfwd02.ndm.nsro:7171 10.40.88.170:50326 TIME_WAIT tcp 0 0 10.40.88.178:7171 poc-card-luna2.nad.ns:50326 TIME_WAIT tcp 0 0 12b8-splfwd02.ndm.nsro:7171 10.30.88.145:50326 ESTABLISHED tcp 0 0 10.40.88.178:7171 poc-card-luna4.nad.ns:50326 SYNC_SENT tcp 0 0 12b8-splfwd03.ndm.nsro:7171 poc-card-luna1.nad.ns:46756 TIME_WAIT tcp 0 0 12b8-splfwd03.ndm.nsro:7171 10.30.88.117:46756 SYNC_SENT tcp 0 0 10.40.88.178:7171 poc-card-luna2.nad.ns:46756 TIME_WAIT tcp 0 0 12b8-splfwd03.ndm.nsro:7171 10.40.83.157:46756 TIME_WAIT tcp 0 0 12b8-splfwd03.ndm.nsro:7171 poc-card-luna4.nad.ns:46756 ESTABLISHED tcp 0 0 12b8-splfwd04.ndm.nsro:7171 poc-card-luna1.nad.ns:46756 TIME_WAIT tcp 0 0 10.40.88.178:7171 poc-card-luna3.nad.ns:46756 SYNC_SENT tcp 0 0 12b8-splfwd04.ndm.nsro:7171 poc-card-luna2.nad.ns:46756 SYNC_SENT tcp 0 0 12b8-splfwd04.ndm.nsro:7171 poc-card-luna4.nad.ns:46756 ESTABLISHED tcp 0 0 12b8-splfwd04.ndm.nsro:7171 poc-card-luna2.nad.ns:46756 ESTABLISHED

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>