Im trying to extract the IP address in the  and the user name which follows it.
I tried a few different regex with no success.,
Any recommendations ?
May 16 15:39:57 192.x.x.x Juniper: 2013-05-16 16:39:58 - ive - [24.x.x.x] bob_b(Company - OTP)[VIT Users] - Key Exchange number 1 occured for user with NCIP 192.x.x.x
Put this in your
props.conf to get it all in one go. Assumes that the ip-address is inside the first set of square brackets in each event, and the username follows immediately after that (well, with a whitespace in between actually). The username can only contain
A-Z, a-z, 0-9, - and
[your sourcetype] EXTRACT-get_stuff = ^[\+\[(?<ip_adress>[\]]+)\]\s+(?<user_name>[-\w]+)