Splunk Rex 005 – match two ip addresses
if the log is having two ip addresses, to match the 2nd ip address, just match the 1st ip address and then, match for the 2nd ipaddress, add the captured field name to the 2nd ip address.
the rex commands are copied to the first comment(as angled brackets are not accepted in the description)
ip address