# Regex pipeline : Get IP from string field

**URL:** <https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294>\
**Category:** Graylog Central (peer support)\
**Created:** [August 30, 2017, 7:38am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294 "2017-08-30T07:38:33Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Loompaz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/loompaz/32/668_2.png) [@Loompaz](https://community.graylog.org/u/Loompaz)\
**Post date:** [August 30, 2017, 7:38am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/1 "2017-08-30T07:38:33Z")

</div>

Hello everybody,

I’m trying to match IP Adress from URL fields :

```
rule "[WIN]Detect IP in URL"
when
    regex"^([0-9]{1,3}\.){3}[0-9]{1,3}$", to_ip($message.url_hostname)).matches == true
then
    set_field("ip_in_url","true");
end

```

The regx is valid. I checked it on [regex101.com](http://regex101.com). However, Graylog doesn’t validate the regex.

Any idea on where is the issue ?

Thanks for your help !

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 30, 2017, 7:55am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/2 "2017-08-30T07:55:58Z")

</div>

You’re missing an opening parenthesis after the `regex` function name.

The regular expression also only matches if the `url_hostname` field contains an IPv4 address without leading or trailing characters. Is that always the case with your messages?

---

<div class="post-metadata">

**Author:** ![Loompaz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/loompaz/32/668_2.png) [@Loompaz](https://community.graylog.org/u/Loompaz)\
**Post date:** [August 30, 2017, 8:18am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/3 "2017-08-30T08:18:16Z")

</div>

Parenthesis fixed thx:

```
rule "[WIN]Detect IP in URL"
when
    regex("^([0-9]{1,3}\.){3}[0-9]{1,3}$", to_ip($message.url_hostname)).matches == true
then
    set_field("ip_in_url","true");
end 

```

However, normally, url\_hostname should NOT contains IPv4 address.  
That’s why I try do detect with this rule when there is some ip adress instead of normal url in the hostname\_url field.  
Use IP and not dns resolution may be considered as suspicious.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 30, 2017, 8:21am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/4 "2017-08-30T08:21:54Z")

</div>

Please post an example message which should be matched by this rule.

---

<div class="post-metadata">

**Author:** ![Loompaz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/loompaz/32/668_2.png) [@Loompaz](https://community.graylog.org/u/Loompaz)\
**Post date:** [August 30, 2017, 8:37am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/5 "2017-08-30T08:37:50Z")

</div>

That’s pretty simple, instead of dns name, the proxy client request an external ip addres.

Normal behavior :  
url\_hostname:google.com

Suspicious behavior that I try to detect using the pipeline :  
url\_hostname:1.2.3.4  
(or url\_hostname: 1.2.3.4:6666)

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 30, 2017, 8:57am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/6 "2017-08-30T08:57:52Z")

</div>

Are there any trailing whitespace characters in the `url_hostname` field?

Also, your regular expression will only match the first example ( `1.2.3.4`) but not the second (`1.2.3.4:6666`).

Additionally, I just see the `to_ip` function in your condition, which is wrong there. Regular expressions only work on _strings_, not IP addresses (the data type, not if a string contains an IP address).

---

<div class="post-metadata">

**Author:** ![Loompaz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/loompaz/32/668_2.png) [@Loompaz](https://community.graylog.org/u/Loompaz)\
**Post date:** [August 30, 2017, 9:08am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/7 "2017-08-30T09:08:10Z")

</div>

No trailing whitespace characters in the url\_hostname field

Yes, this is just a test, I will improve to detect 1.2.3.4:6666

I tried :

```
rule "[WIN]Detect IP in URL"
when
regex("^([0-9]{1,3}\.){3}[0-9]{1,3}$", to_string($message.url_hostname)).matches == true
then
set_field("ip_in_url","true");
end

```

But Graylog does not validate the regex …

Do you think if what I want to do is possible ?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 30, 2017, 9:32am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/8 "2017-08-30T09:32:36Z")

</div>

You have to escape the `\` character (to `\\`).

Also see [http://www.regexplanet.com/advanced/java/index.html](http://www.regexplanet.com/advanced/java/index.html) and [http://www.vogella.com/tutorials/JavaRegularExpressions/article.html#backslashes-in-java](http://www.vogella.com/tutorials/JavaRegularExpressions/article.html#backslashes-in-java)

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [August 30, 2017, 9:40am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/9 "2017-08-30T09:40:32Z")

</div>

1. Why do you use ^ and $ in your regex?
2. Why do you not include the last set of numbers in the IP address in the capturing group?

---

<div class="post-metadata">

**Author:** ![Loompaz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/loompaz/32/668_2.png) [@Loompaz](https://community.graylog.org/u/Loompaz)\
**Post date:** [August 30, 2017, 10:06am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/10 "2017-08-30T10:06:57Z")

</div>

Indeed, no more graylog errors when I escape \ character. I taught escaping was not needed for regex… Thanks for this @jochen ! 😄

---

<div class="post-metadata">

**Author:** ![Loompaz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/loompaz/32/668_2.png) [@Loompaz](https://community.graylog.org/u/Loompaz)\
**Post date:** [August 30, 2017, 10:13am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/11 "2017-08-30T10:13:39Z")

</div>

1-I always use this.  
2-Otherwise, another dot (.) would be expected at the end of the last set of numbers : 1.2.3.4.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 30, 2017, 10:36am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/12 "2017-08-30T10:36:20Z")

</div>

> [@jtkarvo](#):
>
> Why do you use ^ and $ in your regex?

As a rule of thumb, making a regular expression as specific and rigid as possible has advantages regarding performance and resilience.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 13, 2017, 10:36am UTC](https://community.graylog.org/t/regex-pipeline-get-ip-from-string-field/2294/13 "2017-09-13T10:36:38Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
