Regular Expressions 101

Community Patterns

Windows Security Log Event ID 4634

0

Regular Expression
PCRE (PHP <7.3)

/
(?P<event_message>An account was logged off.)\s+Subject:\s+Security ID:\s+(?P<subject_security_id>.*?)\s+Account Name:\s+(?P<subject_account_name>.*?)\s+Account Domain:\s+(?P<subject_account_domain>.*?)\s+Logon ID:\s+(?P<subject_logon_id>.*?)\s+Logon Type:\s+(?P<logon_type>.*?)\s+(?P<event_details>.*)
/
g

Description

An account was logged off

Submitted by anonymous - 7 years ago