re = /\sfor\s(?:invalid\suser\s)?(?<Username>\w+)\s\w+\s(?<IP>[^\s]+)/m
str = 'Thu Sep 07 2021 00:15:06 mailsv1 sshd[2605]: Failed password for invalid user itmadmin from 194.8.74.23 port 4692 ssh2
Thu Sep 07 2021 00:15:06 mailsv1 sshd[3759]: Failed password for nagios from 194.8.74.23 port 3769 ssh2'
# Print the match result
str.scan(re) do |match|
puts match.to_s
end
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Ruby, please visit: http://ruby-doc.org/core-2.2.0/Regexp.html