Filtering on external syslog message.keyword for SRC=aaa.bbb.ccc.ddd IP address

Things are starting to come back. Back in 2017, when my first interest in ELK started, someone helped me with a REGEX filter while in the Kibana window. If my memory serves me, it was a _type filter that had the ability to parse each message and index the IP dotted-quad address. Alas, I lost my notes since then and am trying to recreate the same indexing 4 years later. Anyone with a working process?