re = /(?<comment>(?:\w+\s)+(?:(?<ip>\d{1,255}.\d{1,255}.\d{1,255}.\d{1,255}))\s(?:\w+\s)\d{1,65535}.*)/mx
str = 'Mar 6 17:15:20 Zant sshd[29880] <Error>: error: maximum authentication attempts exceeded for invalid user admin from 190.232.81.120 port 41095 ssh2 [preauth]'
# Print the match result
str.scan(re) do |match|
puts match.to_s
end
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Ruby, please visit: http://ruby-doc.org/core-2.2.0/Regexp.html