如何用正则从两类日志提取源IP并忽略引号方括号
Got it, let's tackle this problem. You need to pull source IP addresses from two log formats: one uses the id.orig_h field (with quoted IPs) and the other uses tx_hosts (with IPs wrapped in brackets and quotes). Here's a tailored regex solution that ignores those extra characters and captures just the IPs.
Final Regex (Simplified, for Valid IPs)
If you're confident all IPs in your logs are valid IPv4 addresses, this regex works perfectly:
(?:id\.orig_h":"|tx_hosts":\["?)((?:\d{1,3}\.){3}\d{1,3})
Breakdown of the Regex
(?:id\.orig_h":"|tx_hosts":\["): A non-capturing group that matches the prefixes for our target fields. It looks for eitherid.orig_h":"(the start of the source IP field in the first log type) ortx_hosts":["(the start of the IP list in the second log type). The?:means we don't capture this part—we only care about the IP itself.((?:\d{1,3}\.){3}\d{1,3}): The capturing group that grabs the IPv4 address.(?:\d{1,3}\.){3}matches three sets of 1-3 digits followed by a dot, and\d{1,3}matches the final octet.
More Strict Regex (For Validating IPs)
If you need to ensure the captured IPs are actually valid (e.g., avoid values like 256.0.0.1), use this more precise version:
(?:id\.orig_h":"|tx_hosts":\["?)((?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?))
This regex validates each octet to ensure it's between 0-255.
How to Use It
In most regex tools (like grep -P, Python's re module, Splunk, etc.), you'll extract the first capturing group (the content inside the outer ()) to get just the IP address.
Tested Against Your Log Samples
For the first log sample:
schema_id=17127524534057985804:skip_writers="":{"_path":"conn","_system_name":"hostname","_write_ts":"2020-01-12T22:09:28.853417Z","ts":"2020-01-12T22:07:14.642074Z","uid":"Cm4cbmvRjlmd2I52c","id.orig_h":"192.168.1.1","id.orig_p":xxx,"id.resp_h":"192.168.1.2","id.resp_p":xxx,"proto":"udp"
Captures:192.168.1.1For the second log sample:
schema_id=17223896091372211545:skip_writers="":{"_path":"files","_system_name":"Hostname","_write_ts":"2020-01-12T22:09:00.016260Z","ts":"2020-01-12T22:07:14.108217Z","fuid":"FnmzOv3Fkhr8lP0qL","tx_hosts":["192.168.1.1","192.168.1.1"],"rx_hosts":["192.168.1.10"]
Captures:192.168.1.1(twice, since there are two identical IPs intx_hosts)
内容的提问来源于stack exchange,提问作者user3704597

