// include the latest version of the regex crate in your Cargo.toml
extern crate regex;
use regex::Regex;
fn main() {
let regex = Regex::new(r"(?m)password\s+for\s+(user|(invalid\s+user))\s+(?<User>\w+)\s+from\s+(?<Source_IP>\d+\.\d+\.\d+\.\d+)\s+port\s+(?<Source_Port>\d+)\s+(?<Protocol>\w+)").unwrap();
let string = "Jun 3 17:29:44 ntp sshd[9668]: Failed password for invalid user XXX from 192.168.111.111 port 63568 ssh2
· host = ntp 192.168.XXX.XXX
· source = /var/log/secure
· sourcetype = linux_secure
Jun 3 17:29:44 XXX sshd[9668]: Failed password for user XXX from 192.168.111.111 port 63568 ssh2
· host = 10.0.0.XXX
· source = /var/log/secure
· sourcetype = linux_secure
Jun 3 00:13:41 XXX sshd[18404]: Accepted password for user XXX from 192.168.111.111 port 60272 ssh2
· host = 10.0.0.XXX
· source = /var/log/secure
· sourcetype = linux_secure";
// result will be an iterator over tuples containing the start and end indices for each match in the string
let result = regex.captures_iter(string);
for mat in result {
println!("{:?}", mat);
}
}
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Rust, please visit: https://docs.rs/regex/latest/regex/