Non-Capturing Group(?:-|(?P<real_ip>[\-\da-f.:]+)) -the literal - (4510 / 558 / 2D16)
2nd Alternative(?P<real_ip>[\-\da-f.:]+) Group real_ip(?P<real_ip>[\-\da-f.:]+) Character Class[\-\da-f.:]+ +matches at least one character from the set below:
\-the literal - (4510 / 558 / 2D16)
\da digit
a-fone character from a (9710) to f (10210) (case sensitive)
.the literal . (4610 / 568 / 2E16)
:the literal : (5810 / 728 / 3A16)
\s+any whitespace character, repeated at least once
\[the literal [ (9110 / 1338 / 5B16)
Group remote_ip(?P<remote_ip>[\da-f.:]+) Character Class[\da-f.:]+ +matches at least one character from the set below:
\da digit
a-fone character from a (9710) to f (10210) (case sensitive)
.the literal . (4610 / 568 / 2E16)
:the literal : (5810 / 728 / 3A16)
\]the literal ] (9310 / 1358 / 5D16)
\s+any whitespace character, repeated at least once
+matches at least one character from the set below:
\wany word character
\.the literal . (4610 / 568 / 2E16)
\-the literal - (4510 / 558 / 2D16)
\s+any whitespace character, repeated at least once
Group remote_user(?<remote_user>\S+) \S+any non-whitespace character, repeated at least once
\s+any whitespace character, repeated at least once
\[the literal [ (9110 / 1338 / 5B16)
Group timestamp(?<timestamp>[^\]]+) Negated Character Class[^\]]+ +matches at least one character outside the set below:
\]the literal ] (9310 / 1358 / 5D16)
\]the literal ] (9310 / 1358 / 5D16)
\s+any whitespace character, repeated at least once
"the literal " (3410 / 428 / 2216)
Non-Capturing Group(?:\-|(?<request>\w+) (?<request_uri>[^ \?]+)(?:\?(?<request_uri_query>[^ ]*))? (?<request_version>[\w\/\.]+)) \-the literal - (4510 / 558 / 2D16)
2nd Alternative(?<request>\w+) (?<request_uri>[^ \?]+)(?:\?(?<request_uri_query>[^ ]*))? (?<request_version>[\w\/\.]+) Group request(?<request>\w+) \w+any word character, repeated at least once
the literal (3210 / 408 / 2016)
Group request_uri(?<request_uri>[^ \?]+) Negated Character Class[^ \?]+ +matches at least one character outside the set below:
the literal (3210 / 408 / 2016)
\?the literal ? (6310 / 778 / 3F16)
Non-Capturing Group(?:\?(?<request_uri_query>[^ ]*))? ?repeats the group contents below at most once:
\?the literal ? (6310 / 778 / 3F16)
Group request_uri_query(?<request_uri_query>[^ ]*) Negated Character Class[^ ]* *matches any number of characters outside the set below:
the literal (3210 / 408 / 2016)
the literal (3210 / 408 / 2016)
Group request_version(?<request_version>[\w\/\.]+) +matches at least one character from the set below:
\wany word character
\/the literal / (4710 / 578 / 2F16)
\.the literal . (4610 / 568 / 2E16)
"the literal " (3410 / 428 / 2216)
\s+any whitespace character, repeated at least once
Group status(?P<status>[1-9]\d{2}) 1-9one character from 1 (4910) to 9 (5710)
\d{2}a digit, repeated exactly 2 times
\s+any whitespace character, repeated at least once
Group body_bytes_sent(?P<body_bytes_sent>\d+) \d+a digit, repeated at least once
\s+any whitespace character, repeated at least once
"the literal " (3410 / 428 / 2216)
Group http_referer(?<http_referer>[^"]+) "the literal " (3410 / 428 / 2216)
\s+any whitespace character, repeated at least once
"the literal " (3410 / 428 / 2216)
Group http_user_agent(?<http_user_agent>[^"]+) "the literal " (3410 / 428 / 2216)
\s+any whitespace character, repeated at least once
\[the literal [ (9110 / 1338 / 5B16)
Non-Capturing Group(?:\-|(?P<upstream_response_time>\d+(?:.\d+)?)) \s+any whitespace character, repeated at least once
Group request_time(?P<request_time>\d+(?:.\d+)?) \]the literal ] (9310 / 1358 / 5D16)
g modifier: global. Finds all matches instead of stopping after the first
m modifier: multiline. Causes ^ and $ to match the start and end of each line, not only the start and end of the string