Hi, I'm sure this is really simple but I've been unable to figure out the exact regex to capture the hostname value from the event logs.
Sample data:
May 29 14:51:56 deast01pano.xxxxx.com 1,2018/05/29 14:51:56,012501001022,6553964590112973819,0x8000000000000000,USERID,login,2049,2018/05/29 14:51:50,0,0,0,0,vsys1,dwest01fw,1,vsys1,10.142.10.172,xxxxx\pulse,deast01fwua.xxxxx.com,0,1,2700,0,0,agent,,0,0,,2018/05/29 14:51:47,1,0,0,0x0,xxxxx\pulse
I want to capture dwest01fw and replace it in the host field. I tried this regex and tested in regex101.com but it failed to capture the host .
USERID,.+,vsys1,(\w+).+$
Transform syntax :
[pan_vsys1_host]
REGEX = USERID,.+,vsys1,(\w+).+$
DEST_KEY = MetaData:Host
FORMAT = host::$1
Kindly guide me on this.
... View more