- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Windows Security logs and USB Monitoring
rduro
New Member
11-01-2011
07:54 AM
Dear All,
I'm trying to find a way to catch the number 0018F3D97D02BBA0517E001A&0 which before the last backslash.
I put an extract of the line I want to a reg on it.
Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\USBSTOR\Disk&Ven_Kingston&Prod_DT_R500&Rev_PMAP\0018F3D97D02BBA0517E001A&0
The reg command I used is the following:
| rex field=_raw "USBSTOR.*_(?<USBID>......?)"|
I just want to extract all data after the last backslash.
Please help,
Best regards,
Raph
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ayn
Legend
11-01-2011
08:17 AM
If that code is the last text in the event, how about:
| rex "(?<USBID>[^\\]+)$"
data:image/s3,"s3://crabby-images/d7f73/d7f73632dd731f9b3dd280d9d048df61ba67932c" alt=""