NetworkMonitoring - parse IP addresses in 'Path' column

%3CLINGO-SUB%20id%3D%22lingo-sub-209447%22%20slang%3D%22en-US%22%3ENetworkMonitoring%20-%20parse%20IP%20addresses%20in%20'Path'%20column%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-209447%22%20slang%3D%22en-US%22%3E%3CP%3EGreetings%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20currently%20evaluating%20the%20features%20in%20the%20%22Network%20Performance%20Monitoring%22%20solution%20for%20Log%20Analytics.%20When%20we%20query%20for%20SubType%20%22EndpointPath%22%2C%20the%20%22Path%22%20column%20has%20great%20detail%20for%20the%20hops%20that%20the%20test%20takes.%20However%2C%20it%20contains%20all%20the%20IP%20addresses%20together%20in%20the%20same%20field.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EExample%20(I've%20masked%20out%20the%20middle%20parts)%3A%3C%2FP%3E%3CBLOCKQUOTE%3E%3CP%3E146.xxx.xxx.31%20146.xxx.xxx.2%20139.xxx.xxx.153%20139.xxx.xxx.241%20139.xxx.xxx.242%20146.xxx.xxx.89%20146.xxx.xxx.166%20139.xxx.xxx.92%20139.xxx.xxx.103%20*%20*%20104.xxx.xxx.191%20104.xxx.xxx.198%20104.xxx.xxx.194%20*%20*%2025.xxx.xxx.15%2025.xxx.xxx.39%2025.xxx.xxx.46%2040.xxx.xxx.34%3C%2FP%3E%3C%2FBLOCKQUOTE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can't%20seem%20to%20figure%20out%20how%20to%20parse%20the%20IP%20addresses%20in%20that%20column%20to%20their%20own%20columns%20(IP1%2C%20IP2%2C%20etc)%20and%20in%20the%20order%20that%20they're%20listed%20in%20the%20column.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20thoughts%2Fideas%20on%20this%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-209447%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetwork%20Performance%20Monitoring%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-211368%22%20slang%3D%22en-US%22%3ERe%3A%20NetworkMonitoring%20-%20parse%20IP%20addresses%20in%20'Path'%20column%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-211368%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20not%2C%20but%20this%20looks%20like%20what%20I%20need.%20Thanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-211109%22%20slang%3D%22en-US%22%3ERe%3A%20NetworkMonitoring%20-%20parse%20IP%20addresses%20in%20'Path'%20column%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-211109%22%20slang%3D%22en-US%22%3EHave%20you%20tried%20using%20the%20split%20with%20space%20as%20separator%3F%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.loganalytics.io%2Fdocs%2FLanguage-Reference%2FScalar-functions%2Fsplit%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.loganalytics.io%2Fdocs%2FLanguage-Reference%2FScalar-functions%2Fsplit%3C%2FA%3E()%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Greetings,

 

We are currently evaluating the features in the "Network Performance Monitoring" solution for Log Analytics. When we query for SubType "EndpointPath", the "Path" column has great detail for the hops that the test takes. However, it contains all the IP addresses together in the same field.

 

Example (I've masked out the middle parts):

146.xxx.xxx.31 146.xxx.xxx.2 139.xxx.xxx.153 139.xxx.xxx.241 139.xxx.xxx.242 146.xxx.xxx.89 146.xxx.xxx.166 139.xxx.xxx.92 139.xxx.xxx.103 * * 104.xxx.xxx.191 104.xxx.xxx.198 104.xxx.xxx.194 * * 25.xxx.xxx.15 25.xxx.xxx.39 25.xxx.xxx.46 40.xxx.xxx.34

 

I can't seem to figure out how to parse the IP addresses in that column to their own columns (IP1, IP2, etc) and in the order that they're listed in the column. 

 

Any thoughts/ideas on this? 

2 Replies
Highlighted
Highlighted

I have not, but this looks like what I need. Thanks!