[ossec-list] Re: Teamviewer logs not consistant

2016-10-14 Thread Jacob Mcgrath
will try ty I think my regex foo was off a bit On Tuesday, October 11, 2016 at 6:41:56 PM UTC-5, Jacob Mcgrath wrote: > > I am looking at logging on a windows agent Teamviewer logs. The issue is > the irregular output like soo. > > 673915615 Support Team20-05-2016 19:37:51 20-05-20

[ossec-list] Re: Teamviewer logs not consistant

2016-10-14 Thread Jesus Linares
Hi, this could be a good starting point: ^\d+\t+\.+\d\d-\d\d-\d\d\d\d teamviewer ^\d+\t\t ^\d+\t+\s*(\.+)\t+(\.+)\t+(\.+)\t+RemoteControl\t+{(\.+)} extra_data,status,srcuser,id teamviewer ^\d+\t ^\d+\t+(\.+)\t+(\.+)\t+(\.+)\t+(\.+)\t+RemoteControl\t+{(\