re = /^[^\u003c\n]*\u003c([^ \u003e]+)[^\-\n]*\-\w+\s+\w+\s+\w+\s+\w+\s+\w+\s+\w+\s+([^ \ ]+)(?:[^\ \n]*\ ){4}([^ ]+)/m
str = '<62>4d19h22m35s:Security: telnet logout by un-authenticated telnet user from src IP 192.168.1.229 from src MAC 28d2.44e4.9c8f from USER EXEC mode
<62>2d00h56m15s:Security: SSH login by nirav from src IP 192.168.1.229 from src MAC 28d2.44e4.9c8f to PRIVILEGED EXEC mode using RSA as Server Host Key.'
# Print the match result
str.scan(re) do |match|
puts match.to_s
end
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Ruby, please visit: http://ruby-doc.org/core-2.2.0/Regexp.html