Regular Expressions 101

Community Patterns

Community Library Entry

0

Regular Expression
Created·2022-02-16 16:33
Updated·2022-02-16 16:40
Flavor·JavaScript

/
\d\s\d+\s\S+\s(?<srcaddr>(?:[0-9]{1,3}\.){3}[0-9]{1,3})\s(?<dstaddr>(?:[0-9]{1,3}\.){3}[0-9]{1,3})\s(?<srcport>\d+)\s(?<dstport>\d+)[\s\d+\s]{1,}(?<action>\w+)\s(?<status>\w+)$
/
gm
Open regex in editor

Description

This will pull out the source, destination IP addresses and the destination port from a default ENI flow log entry.

Submitted by Abram Flansburg