Regular Expressions 101

Community Patterns

Windows Security Log Event ID 4767

0

Regular Expression
PCRE (PHP <7.3)

/
(?P<event_message>A user account was unlocked\.)\s+Subject:\s+Security ID:\s+(?P<subject_security_id>.*?)\s+Account Name:\s+(?P<subject_account_name>.*?)\s+Account Domain:\s+(?P<subject_account_domain>.*?)\s+Logon ID:\s+(?P<subject_logon_id>.*?)\s+Target Account:\s+Security ID:(?P<target_security_id>.*?)\s+Account Name:\s+(?P<target_account_name>.*?)\s+Account Domain:\s+(?P<target_account_domain>.*)
/
g

Description

A user account was unlocked

Submitted by anonymous - 7 years ago