I have this query
| rex field=_raw "(?ms)^[^\]\n]\]\s+(?P [^:]+)(?:[^:\n] :){2}(?P [^,]+)[^:\n]:\w+=(?P [^,]+)[^;\n] ;\w+:(?P [^;]+);\w+:(?P [^;]+)(?:[^:\n]*:){2}\w+\\(?P \w+)"
I was not able to capture everything I wanted ie from the first event below: (I need Severity, Type, Status, Server, DNS, IP, UN, USERID, when unavailable would be blank)
Severity = INFO
Type = DesktopControlJMS
Status = PENDING
Server = cn=c111111f-0111-4111-a111-cc01111111
DNS = gvlcsnav4025.ad.nitro.com
IP = 10.111.111.111
UN = un12802
USERID = cn=s-2-2-22-59222222-343222254-204222229-4722223
I am trying to capture the data from events like this:
2019-01-11T07:41:10.400-06:00 INFO (4440-4444) <DesktopControlJMS> [Audit] PENDING:Server:cn=c111111f-0111-4111-a111-cc01111111,ou=servers,dc=vdi,dc=vm,dc=int;Pool:cn=gvlcsnav4,ou=server groups,dc=vdi,dc=vm,dc=int;DNS:gvlcsnav4025.ad.nitro.com;IP:10.111.111.111;IP6:null;USER:LP\un12802;USERDN:cn=s-2-2-22-59222222-343222254-204222229-4722223,cn=foreignsecurityprincipals,dc=vdi,dc=vm,dc=int;BROKERUSERSID:s-2-2-22-59222222-343222254-204222229-4722223;
2019-01-11T07:46:06.049-06:00 INFO (4444-1300) <DesktopControlJMS> [Audit] STARTUP:Server:cn=eeeeed6-eeeb2-eee3-beed-56eeeeeeeb77,ou=servers,dc=vdi,dc=vm,dc=int;Pool:cn=gvclsnav2,ou=server groups,dc=vdi,dc=vm,dc=int;DNS:gvclsnav2069.ad.nitro.com;IP:10.990.999.1;IP6:null;
2019-01-11T07:36:03.140-06:00 INFO (1444-0622) <MachineControler> [Audit] PENDING:Server:cn=7677778c-d777-4777-a777-587777772d,ou=servers,dc=vdi,dc=vm,dc=int;Pool:cn=gvsview01,ou=server groups,dc=vdi,dc=vm,dc=int;DNS:gvsview030276.ad.nitro.com;IP:10.122.222.221;IP6:null;USER:LP\UNVA33E;USERDN:cn=s-2-2-22-5999990-343999999-204999989-469993,cn=foreignsecurityprincipals,dc=vdi,dc=vm,dc=int;BROKERUSERSID:s-2-2-22-5999990-343999999-204999989-469993;
Any suggestions or ideas would be greatly appreciated!!
... View more