# How to use Regex

**URL:** <https://community.graylog.org/t/how-to-use-regex/3967>\
**Category:** Graylog Central (peer support)\
**Tags:** sidecar, nxlog, winlogbeat, nodatanx, multi-linenx\
**Created:** [January 29, 2018, 6:10pm UTC](https://community.graylog.org/t/how-to-use-regex/3967 "2018-01-29T18:10:29Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndreasD](https://avatars.discourse-cdn.com/v4/letter/a/82dd89/32.png) [@AndreasD](https://community.graylog.org/u/AndreasD)\
**Post date:** [January 29, 2018, 6:10pm UTC](https://community.graylog.org/t/how-to-use-regex/3967/1 "2018-01-29T18:10:29Z")

</div>

Hey Guys,

how can I filter the **Account Name: srvmeldedmz** out of the full message in graylog.

please take a look at the picture.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/c/c84d7c055f38ecd1736cdc25513b08866e236887.png)

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [January 29, 2018, 7:16pm UTC](https://community.graylog.org/t/how-to-use-regex/3967/2 "2018-01-29T19:16:22Z")

</div>

You can try something like this:

`Account Name:[\s]*([^\s]*)`

---

<div class="post-metadata">

**Author:** ![AndreasD](https://avatars.discourse-cdn.com/v4/letter/a/82dd89/32.png) [@AndreasD](https://community.graylog.org/u/AndreasD)\
**Post date:** [January 29, 2018, 7:30pm UTC](https://community.graylog.org/t/how-to-use-regex/3967/3 "2018-01-29T19:30:51Z")

</div>

> [@jtkarvo](#):
>
> Account Name:[\s]_([^\s]_)

Hey thank you very much but, the result is the first Account Name: SBG-MELDET$ and not the Account Name: srvmeldedmz

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [January 29, 2018, 8:54pm UTC](https://community.graylog.org/t/how-to-use-regex/3967/4 "2018-01-29T20:54:22Z")

</div>

What type of message is that and is that information available in a structured manner?  
How are you ingesting these messages into Graylog?

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [January 30, 2018, 3:55pm UTC](https://community.graylog.org/t/how-to-use-regex/3967/5 "2018-01-30T15:55:18Z")

</div>

Indeed. If you import the log lines in Gelf, the SubjectUserName, TargetUserName field etc. are automatically extracted.

If that is not possible, there are many, many, many ways to achieve what you want.

For example: first extract the whole “Account For Which Logon Filed” section to the target field (or variable in a processing pipeline) with something like

`Account For Which Logon Failed:(>?(.*))Failure Information`

, and then use replace with regex extractor or match with the regex I gave earlier in a pipeline.

---

<div class="post-metadata">

**Author:** ![nomoresecrets](https://avatars.discourse-cdn.com/v4/letter/n/ac8455/32.png) [@nomoresecrets](https://community.graylog.org/u/nomoresecrets)\
**Post date:** [January 30, 2018, 4:38pm UTC](https://community.graylog.org/t/how-to-use-regex/3967/6 "2018-01-30T16:38:52Z")

</div>

I strongly recommend to use a tool like nxlog to get your windows logs shipped in GELF to graylog. It makes life so much easier than writing regexes

---

<div class="post-metadata">

**Author:** ![AndreasD](https://avatars.discourse-cdn.com/v4/letter/a/82dd89/32.png) [@AndreasD](https://community.graylog.org/u/AndreasD)\
**Post date:** [January 31, 2018, 8:12am UTC](https://community.graylog.org/t/how-to-use-regex/3967/7 "2018-01-31T08:12:15Z")

</div>

Hey this is a Windows Event Log. I use NXLog to send it to my graylog Server.

---

<div class="post-metadata">

**Author:** ![AndreasD](https://avatars.discourse-cdn.com/v4/letter/a/82dd89/32.png) [@AndreasD](https://community.graylog.org/u/AndreasD)\
**Post date:** [January 31, 2018, 8:17am UTC](https://community.graylog.org/t/how-to-use-regex/3967/8 "2018-01-31T08:17:57Z")

</div>

Hey I do use NXLog to ship my windows logs to my graylog server.  
This is my nxlog.conf

I also tried to send Log-Messages from “meldewesen.log” via GELF put this doesn´t work because  
the Log File includes multiline Messages. There is definitly a way but I couldn´t find a solution yet.

```
## This is a sample configuration file. See the nxlog reference manual about the
## configuration options. It should be installed locally and is also available
## online at http://nxlog.org/docs/

## Please set the ROOT to the folder your nxlog was installed into,
## otherwise it will not start.

#define ROOT C:\Program Files\nxlog
define ROOT C:\Program Files (x86)\nxlog

Moduledir %ROOT%\modules
CacheDir %ROOT%\data
Pidfile %ROOT%\data\nxlog.pid
SpoolDir %ROOT%\data
LogFile %ROOT%\data\nxlog.log

<Extension gelf>
    #Module xm_syslog
	Module xm_gelf			
</Extension>

<Input in1>
   Module im_mseventlog
</Input>

#<Input in2>
#	Module im_file
#	File "C:\Meldewesen\log\meldewesen\meldewesen.log"
#	SavePos FALSE
#</Input>

<Output out>
    Module om_tcp
    Host 172.20.42.15
    Port 12210
    #Exec to_syslog_snare();
	OutputType	GELF_TCP
</Output>

<Route 1>
    Path in1 => out
</Route>
```

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [January 31, 2018, 9:12am UTC](https://community.graylog.org/t/how-to-use-regex/3967/9 "2018-01-31T09:12:49Z")

</div>

> [@AndreasD](#):
>
> Module im\_mseventlog

Which version of Windows are you running?

Also make sure to read [NXLog Community Edition Reference Manual | NXLog Docs](https://nxlog.co/docs/nxlog-ce/nxlog-reference-manual.html#im_mseventlog) and [NXLog Community Edition Reference Manual | NXLog Docs](https://nxlog.co/docs/nxlog-ce/nxlog-reference-manual.html#im_msvistalog)

FWIW, personally I like Winlogbeat better than NXLOG for fetching Windows Event Logs.

> [@AndreasD](#):
>
> I also tried to send Log-Messages from “meldewesen.log” via GELF put this doesn´t work because
> 
> the Log File includes multiline Messages.

- [NXLog Community Edition Reference Manual | NXLog Docs](https://nxlog.co/docs/nxlog-ce/nxlog-reference-manual.html#xm_multiline)
- [Managing Multiline Messages | Filebeat Reference [5.6] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/5.6/multiline-examples.html)

---

<div class="post-metadata">

**Author:** ![AndreasD](https://avatars.discourse-cdn.com/v4/letter/a/82dd89/32.png) [@AndreasD](https://community.graylog.org/u/AndreasD)\
**Post date:** [February 2, 2018, 8:01am UTC](https://community.graylog.org/t/how-to-use-regex/3967/10 "2018-02-02T08:01:58Z")

</div>

I am running a Windwos Microsoft Windows Server 2008 R2 VM.

---

<div class="post-metadata">

**Author:** ![Karlis](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/karlis/32/4798_2.png) [@Karlis](https://community.graylog.org/u/Karlis)\
**Post date:** [February 2, 2018, 9:09am UTC](https://community.graylog.org/t/how-to-use-regex/3967/11 "2018-02-02T09:09:34Z")

</div>

in\_mseventlog is for Windows 2003/XP. For Windows 2008 change it to im\_msvistalog

> [@AndreasD](#):
>
> \<Input in1\>  
> Module im\_mseventlog  
> \</Input\>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [February 16, 2018, 9:09am UTC](https://community.graylog.org/t/how-to-use-regex/3967/12 "2018-02-16T09:09:36Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
