^start of line
<142>the literal text <142> Group date(?P<date>\w+\s+\d+) \w+any word character, repeated at least once
\s+any whitespace character, repeated at least once
\d+a digit, repeated at least once
\s+any whitespace character, repeated at least once
Group time(?P<time>[^ ]+) Negated Character Class[^ ]+ +matches at least one character outside the set below:
the literal (3210 / 408 / 2016)
\s+any whitespace character, repeated at least once
Group server(?P<server>\w+) \w+any word character, repeated at least once
\s+any whitespace character, repeated at least once
Group process_name(?P<process_name>[a-z]+) +matches at least one character from the set below:
a-zone character from a (9710) to z (12210) (case sensitive)
\[the literal [ (9110 / 1338 / 5B16)
Group process_number(?P<process_number>\d+) \d+a digit, repeated at least once
Negated Character Class[^ \n]* *matches any number of characters outside the set below:
the literal (3210 / 408 / 2016)
\na line-feed (newline) character (ASCII 10)
the literal (3210 / 408 / 2016)
Group process_id(?P<process_id>[^\|]+) Negated Character Class[^\|]+ +matches at least one character outside the set below:
\|the literal | (12410 / 1748 / 7C16)
\|the literal | (12410 / 1748 / 7C16)
Group message_id(?P<message_id>[^\|]+) Negated Character Class[^\|]+ +matches at least one character outside the set below:
\|the literal | (12410 / 1748 / 7C16)
\|the literal | (12410 / 1748 / 7C16)
Group action(?P<action>IRCPTACTION|VERDICT|UNTESTED|FIRED|SENDER|LOGICAL_IP|EHLO|MSG_SIZE|MSGID|SOURCE|SUBJECT|ORCPTS|TRACKERID|ATTACH|UNSCANNABLE|VIRUS|DELIVER|ACCEPT) 1st AlternativeIRCPTACTION IRCPTACTIONthe literal text IRCPTACTION (case sensitive) VERDICTthe literal text VERDICT (case sensitive) UNTESTEDthe literal text UNTESTED (case sensitive) FIREDthe literal text FIRED (case sensitive) SENDERthe literal text SENDER (case sensitive) 6th AlternativeLOGICAL_IP LOGICAL_IPthe literal text LOGICAL_IP (case sensitive) EHLOthe literal text EHLO (case sensitive) MSG_SIZEthe literal text MSG_SIZE (case sensitive) MSGIDthe literal text MSGID (case sensitive) SOURCEthe literal text SOURCE (case sensitive) SUBJECTthe literal text SUBJECT (case sensitive) ORCPTSthe literal text ORCPTS (case sensitive) 13th AlternativeTRACKERID 15th AlternativeUNSCANNABLE Non-Capturing Group(?:(?:(?<=ACCEPT|DELIVER|LOGICAL_IP)\|(?P<src>[^:\s]+)(?::(?P<port>[0-9]+))?(?:\|(?P<to>[^\s]+))?)|(?:(?<=FIRED|IRCPTACTION|ORCPTS|TRACKERID|UNTESTED|VERDICT)\|(?P<recipient>[^\s\|]+)(?:\|)?(?P<result>[a-z][^\|\s]+)?(?:\|(?P<result_2>[a-z][^\|]+))?(?:\|(?P<result_3>.+))?)|(?:(?<=SENDER)\|(?P<from>[^\s]+))|(?:(?<=MSG_SIZE)\|(?P<msg_size>\w+))|(?:(?<=SUBJECT)\|(?P<subject>.*))|(?:(?<=ATTACH)\|(?P<attachment>.+))|(?:(?<=UNSCANNABLE)\|(?P<reason>.+))|(?:(?<=VIRUS)\|(?P<virus_name>.+))|(?:(?<=EHLO)\|(?P<fqdn>.+)))? g modifier: global. Finds all matches instead of stopping after the first
m modifier: multiline. Causes ^ and $ to match the start and end of each line, not only the start and end of the string