Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Is it possible to put a conditional statement in a field extraction?

$
0
0
I have files I am ingesting that have variable formats. I want to pick those lines out that only have an IP address as the third value and extract that as **srcIP**. Is this possible to essentially put a conditional statement in so I don't get all the garbage from the "other" data in the logs?

Viewing all articles
Browse latest Browse all 47296

Trending Articles