Regular Expressions 101

Community Patterns

cisco_syslog_regex

0

Regular Expression
PCRE (PHP <7.3)

/
^([^\s]+)\s([^\s]+)\s([^\s]+)\s([^\s]+)\s+(?<server>[^\s]+)\s+\*(?<task>[^\s]+\:)\s+([^\s]+)\s+([^\s]+)\s+([^\s]+)\s+\%(?<status>[^\s]+)\s+(?<task1>[^\s]+)\s+(?<action>[^\s]+\')\s+\w+\s+\w+\:\s+(?<src_mac>[^\s]+)\s+\w+\s+\w+\:\s+(?<dest_mac>[^\s]+)\s+\w+\s\'\w+\'\s+(?<tast2>)\w+\s+\'(?<action2>[^\s]+)\s+\w+\s+\'\w+\'\s+\w+\s+\w+\s+\'(?<timesec>[^\s]+)\s+\w+
/
g

Description

^([^\s]+)\s([^\s]+)\s([^\s]+)\s([^\s]+)\s+(?<server>[^\s]+)\s+*(?<task>[^\s]+:)\s+([^\s]+)\s+([^\s]+)\s+([^\s]+)\s+%(?<status>[^\s]+)\s+(?<task1>[^\s]+)\s+(?<action>[^\s]+')\s+\w+\s+\w+:\s+(?<src_mac>[^\s]+)\s+\w+\s+\w+:\s+(?<dest_mac>[^\s]+)\s+\w+\s'\w+'\s+(?<tast2>)\w+\s+'(?<action2>[^\s]+)\s+\w+\s+'\w+'\s+\w+\s+\w+\s+'(?<timesec>[^\s]+)\s+\w+

Submitted by anonymous - 7 years ago