Trying to construct a rule to match [cb/sl]-srv-[1-#]
rule "identify servers"
has_field("source") AND to_bool(regex(("/\b(cb|sl)-srv-cas\\d*\b/ gmi"),
to_string($message.source)).matches == true)
I have checked the regex part, which works, but having trouble with the syntaxt I think.
Tested http://grokconstructor.appspot.com/do/match#result working fine
you need to escape
\ in regex - and possible double escape to make this work
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.