Skip to content

Commit c8a36b0

Browse files
authored
Merge pull request ossec#1874 from ddpbsd/win_decoder_pcre
pcre2 fix for windows1 decoders
2 parents 0e70ff3 + 811bdfc commit c8a36b0

1 file changed

Lines changed: 2 additions & 3 deletions

File tree

etc/decoder.xml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2030,18 +2030,17 @@ Jan 8 19:32:41 tp.lan dropbear[15165]: Pubkey auth succeeded for 'root' with ke
20302030
<decoder name="windows1">
20312031
<type>windows</type>
20322032
<parent>windows</parent>
2033-
<pcre2> Account Name:[ ]+?([A-Za-z0-9@_-]+?.+)[ ]+?Account</pcre2>
2033+
<pcre2> Account Name:[ ]+?([A-Za-z0-9@_-]+?)[ ]+?Account</pcre2>
20342034
<order>user</order>
20352035
</decoder>
20362036

20372037
<decoder name="windows1">
20382038
<type>windows</type>
20392039
<parent>windows</parent>
2040-
<pcre2>Account Domain:[ ][ ]+?([A-Za-z0-9@_-].+)[ ][ ]+?Logon ID:</pcre2>
2040+
<pcre2>Account Domain:[ ]+?([A-Za-z0-9@_-]+?)[ ]+?Logon ID:</pcre2>
20412041
<order>extra_data</order>
20422042
</decoder>
20432043

2044-
20452044
<!-- Windows decoder -NTsyslog format
20462045
- Will extract extra_data (as win source),action (as win category), id,
20472046
- username and computer name (as url).

0 commit comments

Comments
 (0)