use strict;
my $str = '--- p0f 3.08b by Michal Zalewski <lcamtuf@coredump.cx> ---
[+] Closed 3 file descriptors.
[+] Loaded 324 signatures from \'/etc/p0f/p0f.fp\'.
[+] Will read pcap data from file \'temp.pcap\'.
[+] Default packet filtering configured [+VLAN].
[+] Processing capture data.
.-[ 10.0.7.20/44964 -> 216.58.208.37/443 (syn) ]-
|
| client = 10.0.7.20/44964
| os = Linux 3.11 and newer
| dist = 0
| params = none
| raw_sig = 4:64+0:0:1460:mss*20,7:mss,sok,ts,nop,ws:df,id+:0
|
`----
.-[ 10.0.7.20/44964 -> 216.58.208.37/443 (mtu) ]-
|
| client = 10.0.7.20/44964
| link = Ethernet or modem
| raw_mtu = 1500
|
`----
';
my $regex = qr/os\s*= (.*)/p;
if ( $str =~ /$regex/ ) {
print "Whole match is ${^MATCH} and its start/end positions can be obtained via \$-[0] and \$+[0]\n";
# print "Capture Group 1 is $1 and its start/end positions can be obtained via \$-[1] and \$+[1]\n";
# print "Capture Group 2 is $2 ... and so on\n";
}
# ${^POSTMATCH} and ${^PREMATCH} are also available with the use of '/p'
# Named capture groups can be called via $+{name}
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Perl, please visit: http://perldoc.perl.org/perlre.html