|
^(?>[^<]+)<(?>[^:]+):(?<severity>[^>]+)>.*?LogRhythmDpi: EVT:001 (?<session>\S+):\S+ <sip>,<dip>,<sport>,<dport>,<smac>,<dmac>,<protnum>,((?<vmid>\d+)|(?<process>[^,]*)),(<bytesin>(/\d+)?)?,(<bytesout>(/\d+)?)?,(<packetsin>(/\d+)?)?,[^,]*,[^,]*,((?<seconds>\d+)(/\d+)?)?(.*?(?<=,)login=(?<login>[^$,]*)(,|$))?(.*?(?<=,)domain=(?<domain>.*?)(,|$))?(.*?dname=(?<group>[^$,]*)(,|$))?(.*?command=(?<command>[^$,]*)(,|$))?(.*?sender=((?<sender>support@logrhythm.com),|.*?<(?<sender>.*?)>,|(?<sender>.*?),))?(.*?recipient=(.*?<(?<recipient>.*?)>,|(?<recipient>.*?),|"<recipient>"))?(.*?subject=(?<subject>.*?)(,|$))?(.*?(?<=,)version=(?<version>.*?)(,|$))?(.*?object=(/+|(?<object>.*?)(?=,url=)|(?<object>[^$,]*))(,|$))?(.*?objectname=(?<objectname>[^$,]*)(,|$))?(.*?url=(/+|(?<url>[^$,]*))(,|$))?
|