# Pipeline hangup

**URL:** <https://community.graylog.org/t/pipeline-hangup/24803>\
**Category:** Graylog Central (peer support)\
**Created:** [July 15, 2022, 2:48pm UTC](https://community.graylog.org/t/pipeline-hangup/24803 "2022-07-15T14:48:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![d2freak82](https://avatars.discourse-cdn.com/v4/letter/d/cc9497/32.png) [@d2freak82](https://community.graylog.org/u/d2freak82)\
**Post date:** [July 15, 2022, 2:48pm UTC](https://community.graylog.org/t/pipeline-hangup/24803/1 "2022-07-15T14:48:14Z")

</div>

So what I’m trying to do is extract an ip address from my log - which seems simple enough until you realize there’s 4-5 of them in each log.  
So essentially I want it to look for … which you would use regex .+ for that, at least I assume so. Then directly after those 3 dots extract the ip address.

```auto
Rule "Extract Source IP"
when
     regex(\.+), "...".matches=true
then
     extract the ipv4 address after those dots
set_field("src_ip, to_don'tknow.extractedipaddress")
end

```

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 15, 2022, 10:34pm UTC](https://community.graylog.org/t/pipeline-hangup/24803/2 "2022-07-15T22:34:10Z")

</div>

Hello,

I was going to suggest using GROK, but since there are 4-5 IP address, if I’m correct, I’m not sure.

Have you tried asking HowTo in Graylog Discord?

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 16, 2022, 2:32am UTC](https://community.graylog.org/t/pipeline-hangup/24803/3 "2022-07-16T02:32:30Z")

</div>

I found this, perhaps it will help.

> [@Pipeline rule to generate a Object field with obtained IPs (multi\_value) for a QNAME, from a DNS LookUp Table](https://community.graylog.org/t/pipeline-rule-to-generate-a-object-field-with-obtained-ips-multi-value-for-a-qname-from-a-dns-lookup-table/14921/11):
>
> Spent too long on this, here is what I came up with: let lookup\_IPs\_json = parse\_json(to\_string(lookup("DNS\_QNAME\_IP", to\_string(message.QNAME)))); debug(concat("Initial json: ", to\_string(lookup\_IPs\_json))); let the\_ips = select\_jsonpath(json: lookup\_IPs\_json, paths: { QNAME\_IP: "$['string list value']" }); debug(concat("Set to fields: ", to\_string(the\_ips))); set\_fields(the\_ips);

---

<div class="post-metadata">

**Author:** ![swirt](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@swirt](https://community.graylog.org/u/swirt)\
**Post date:** [July 19, 2022, 2:26am UTC](https://community.graylog.org/t/pipeline-hangup/24803/4 "2022-07-19T02:26:27Z")

</div>

It would be helpful if you could post a sample of the log you are trying to extract an IP address for. Otherwise, here is an untested pipeline rule that may get you what you need:

```auto
rule "Extract Source IP"
when
    regex(".+?[.]{3}(\\d+\\.\\d+\\.\\d+\\.\\d+)", to_string($message.message)).matches == true
then
    let m = to_string($message.message);
    let fields = regex(".+?[.]{3}(\\d+\\.\\d+\\.\\d+\\.\\d+)", to_string($message.message), ["src_ip"]);
    set_fields(fields);
end

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 2, 2022, 2:26am UTC](https://community.graylog.org/t/pipeline-hangup/24803/5 "2022-08-02T02:26:29Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
