# Parsing ip address coming at random places inside logs

**URL:** <https://discuss.elastic.co/t/parsing-ip-address-coming-at-random-places-inside-logs/259177>\
**Category:** Logstash\
**Created:** [December 19, 2020, 8:28pm UTC](https://discuss.elastic.co/t/parsing-ip-address-coming-at-random-places-inside-logs/259177 "2020-12-19T20:28:16Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 20, 2020, 4:05pm UTC](https://discuss.elastic.co/t/parsing-ip-address-coming-at-random-places-inside-logs/259177/5 "2020-12-20T16:05:12Z")

</div>

In you want to capture every occurrence of a regexp in a field then use a ruby filter and the String.scan function.

```
    ruby {
        code => 'event.set("anArray", event.get("message").scan(/(?<![0-9])(?:(?:[0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5])[.](?:[0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5])[.](?:[0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5])[.](?:[0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5]))(?![0-9])/))'
    }

```

Edited to add: The grok pattern for IPV4 is one of the [core patterns](https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/grok-patterns).

---

_[View the full topic](https://discuss.elastic.co/t/parsing-ip-address-coming-at-random-places-inside-logs/259177)._
