File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -2022,18 +2022,17 @@ Jan 8 19:32:41 tp.lan dropbear[15165]: Pubkey auth succeeded for 'root' with ke
20222022<decoder name =" windows1" >
20232023 <type >windows</type >
20242024 <parent >windows</parent >
2025- <pcre2 > Account Name:[ ]+?([A-Za-z0-9@_-]+?.+ )[ ]+?Account</pcre2 >
2025+ <pcre2 > Account Name:[ ]+?([A-Za-z0-9@_-]+?)[ ]+?Account</pcre2 >
20262026 <order >user</order >
20272027</decoder >
20282028
20292029<decoder name =" windows1" >
20302030 <type >windows</type >
20312031 <parent >windows</parent >
2032- <pcre2 >Account Domain:[ ][ ] +?([A-Za-z0-9@_-].+)[ ] [ ]+?Logon ID:</pcre2 >
2032+ <pcre2 >Account Domain:[ ]+?([A-Za-z0-9@_-]+?) [ ]+?Logon ID:</pcre2 >
20332033 <order >extra_data</order >
20342034</decoder >
20352035
2036-
20372036<!-- Windows decoder -NTsyslog format
20382037 - Will extract extra_data (as win source),action (as win category), id,
20392038 - username and computer name (as url).
You can’t perform that action at this time.
0 commit comments