Regular Expressions 101

Community Patterns

Community Library Entry

1

Regular Expression
Created·2024-06-13 14:52
Flavor·PCRE2 (PHP)

/
^[""]*<(?<alert_type>\d+)>(?<timestamp>.*\d+:\d+:\d+)\s(?<tenable_instance_hostname>[^""]+)\s(?<tenable_product_name>[^""]+)\[\d+\]:[\s""]*(?<tenable_internal_mtype>[^""]+)[""\s]*(?<tenable_internal_alertid>\d+)[""\s]*(?<ad_forest_name>[^""]+)[""\s]*(?<ad_domain_name>[^""]+)[""\s]*(?<ad_attack_name>[^""]+)[""\s]*(?<tenable_severity_level>[^""]+)[""\s]*(?<source_name>[^""]+)[""\s]*(?<source_ip>[^""]+)[""\s]*(?<destination_name>[^""]+)[""\s]*(?<destination_ip>[^""]+)[""]*\s(?<tenable_insertion_strings>.*?)$
/
gm
Open regex in editor

Description

A regex for IOA syslog messages sent by Tenable Identity Exposure.

Submitted by Taher Karaki