\<the literal < (6010 / 748 / 3C16)
EventIDthe literal text EventID (case sensitive) \>the literal > (6210 / 768 / 3E16)
4656the literal text 4656 \<the literal < (6010 / 748 / 3C16)
\/the literal / (4710 / 578 / 2F16)
EventIDthe literal text EventID (case sensitive) \>the literal > (6210 / 768 / 3E16)
.*any character (except for line terminators), repeated any number of times
\<the literal < (6010 / 748 / 3C16)
Data Namethe literal text Data Name (case sensitive) \=the literal = (6110 / 758 / 3D16)
\'the literal ' (3910 / 478 / 2716)
ProcessNamethe literal text ProcessName (case sensitive) \'the literal ' (3910 / 478 / 2716)
\>the literal > (6210 / 768 / 3E16)
Cthe literal C (6710 / 1038 / 4316) (case sensitive)
Dthe literal D (6810 / 1048 / 4416) (case sensitive)
Ethe literal E (6910 / 1058 / 4516) (case sensitive)
Fthe literal F (7010 / 1068 / 4616) (case sensitive)
:the literal : (5810 / 728 / 3A16)
\\the literal \ (9210 / 1348 / 5C16)
Windowsthe literal text Windows (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
System32the literal text System32 (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
CpqMgmtthe literal text CpqMgmt (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
cqmghostthe literal text cqmghost (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
cqmghostthe literal text cqmghost (case sensitive) \.the literal . (4610 / 568 / 2E16)
exethe literal text exe (case sensitive) g modifier: global. Finds all matches instead of stopping after the first
m modifier: multiline. Causes ^ and $ to match the start and end of each line, not only the start and end of the string