# Extract IPv4 from ubuntu syslog message

**URL:** <https://community.graylog.org/t/extract-ipv4-from-ubuntu-syslog-message/15286>\
**Category:** Graylog Central (peer support)\
**Created:** [May 6, 2020, 8:42pm UTC](https://community.graylog.org/t/extract-ipv4-from-ubuntu-syslog-message/15286 "2020-05-06T20:42:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_lluis](https://avatars.discourse-cdn.com/v4/letter/_/f6c823/32.png) [@\_lluis](https://community.graylog.org/u/_lluis)\
**Post date:** [May 6, 2020, 8:42pm UTC](https://community.graylog.org/t/extract-ipv4-from-ubuntu-syslog-message/15286/1 "2020-05-06T20:42:30Z")

</div>

Hello,  
I’ve reviewed a few different posts on here to try and figure out how to create a regex extractor to pull an IP address from a message that is being forwarded from a client ubuntu machine into Graylog but am falling short of getting anything to successfully pass the test. Any help is greatly appreciated.

Message I am pulling from “Accepted password for admin from 192.168.1.5 port 61473 ssh2”

I have tried the following regex from another post and it does not pass the example test

[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}

If there is a better way of doing this such as a grok lookup let me know.

Thank you

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [May 6, 2020, 8:53pm UTC](https://community.graylog.org/t/extract-ipv4-from-ubuntu-syslog-message/15286/2 "2020-05-06T20:53:27Z")

</div>

Look at IPV4 under system/grok patterns in Graylog…

---

<div class="post-metadata">

**Author:** ![cawfehman](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/cawfehman/32/4132_2.png) [@cawfehman](https://community.graylog.org/u/cawfehman)\
**Post date:** [May 7, 2020, 7:18pm UTC](https://community.graylog.org/t/extract-ipv4-from-ubuntu-syslog-message/15286/3 "2020-05-07T19:18:45Z")

</div>

couple things…

That is a valid RegEx for capturing an IP address… but it will capture things that are not valid IP addresses. 378.9.456.840 would be a valid result of that regex. but is obviously not a valid IP, so be aware of that.

This is a version of that which will only capture valid IPs

(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5]).){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])

As @tmacgbay mentioned, check out the groks for IPV4. and keep in mind that GROKing the IP is pretty trivial.

from %[IPV4:SrcIP]

would capture that IP.

---

<div class="post-metadata">

**Author:** ![\_lluis](https://avatars.discourse-cdn.com/v4/letter/_/f6c823/32.png) [@\_lluis](https://community.graylog.org/u/_lluis)\
**Post date:** [May 7, 2020, 8:03pm UTC](https://community.graylog.org/t/extract-ipv4-from-ubuntu-syslog-message/15286/4 "2020-05-07T20:03:02Z")

</div>

Thank you to the both of you. Did not realize that the grok patterns were that easy to use. Really appreciate the help. Its working now with the grok lookup.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 21, 2020, 8:03pm UTC](https://community.graylog.org/t/extract-ipv4-from-ubuntu-syslog-message/15286/5 "2020-05-21T20:03:10Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
