You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用正则从两类日志提取源IP并忽略引号方括号

Solution to Extract Source IPs from Logs

Got it, let's tackle this problem. You need to pull source IP addresses from two log formats: one uses the id.orig_h field (with quoted IPs) and the other uses tx_hosts (with IPs wrapped in brackets and quotes). Here's a tailored regex solution that ignores those extra characters and captures just the IPs.

Final Regex (Simplified, for Valid IPs)

If you're confident all IPs in your logs are valid IPv4 addresses, this regex works perfectly:

(?:id\.orig_h":"|tx_hosts":\["?)((?:\d{1,3}\.){3}\d{1,3})

Breakdown of the Regex

  • (?:id\.orig_h":"|tx_hosts":\["): A non-capturing group that matches the prefixes for our target fields. It looks for either id.orig_h":" (the start of the source IP field in the first log type) or tx_hosts":[" (the start of the IP list in the second log type). The ?: means we don't capture this part—we only care about the IP itself.
  • ((?:\d{1,3}\.){3}\d{1,3}): The capturing group that grabs the IPv4 address. (?:\d{1,3}\.){3} matches three sets of 1-3 digits followed by a dot, and \d{1,3} matches the final octet.

More Strict Regex (For Validating IPs)

If you need to ensure the captured IPs are actually valid (e.g., avoid values like 256.0.0.1), use this more precise version:

(?:id\.orig_h":"|tx_hosts":\["?)((?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?))

This regex validates each octet to ensure it's between 0-255.

How to Use It

In most regex tools (like grep -P, Python's re module, Splunk, etc.), you'll extract the first capturing group (the content inside the outer ()) to get just the IP address.

Tested Against Your Log Samples

  1. For the first log sample:

    schema_id=17127524534057985804:skip_writers="":{"_path":"conn","_system_name":"hostname","_write_ts":"2020-01-12T22:09:28.853417Z","ts":"2020-01-12T22:07:14.642074Z","uid":"Cm4cbmvRjlmd2I52c","id.orig_h":"192.168.1.1","id.orig_p":xxx,"id.resp_h":"192.168.1.2","id.resp_p":xxx,"proto":"udp"
    Captures: 192.168.1.1

  2. For the second log sample:

    schema_id=17223896091372211545:skip_writers="":{"_path":"files","_system_name":"Hostname","_write_ts":"2020-01-12T22:09:00.016260Z","ts":"2020-01-12T22:07:14.108217Z","fuid":"FnmzOv3Fkhr8lP0qL","tx_hosts":["192.168.1.1","192.168.1.1"],"rx_hosts":["192.168.1.10"]
    Captures: 192.168.1.1 (twice, since there are two identical IPs in tx_hosts)

内容的提问来源于stack exchange,提问作者user3704597

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 10:48:13