Regular expression pattern matching examples
snmp-server community public
Finds any line that includes the text
snmp-server community public. There can be text before and/or after the string on the same line.
service tcp-keepalives-in.*\n(.*\n)*.*service tcp-keepalives-out>
Finds the first line
service tcp-keepalives-in and then looks for
service tcp-keepalives-out on any line after that. The regular expression string
n(.*\n)*.* is used to search any number of lines between strings.
access-list 105 deny.*tcp any any eq 139 log
Finds the line with
access-list 105 deny, followed by any number of characters of any type, followed by
tcp any any eq 139 log on the same line. The regular expression string
.* finds any character and any number of characters on the same line. This expression can be used to find spaces, tabs, numbers, letters, or special characters.
ntp clock-period \d*
Finds any line that includes
ntp clock-period, followed by any number. The regular expression string
\d* will find any number at any length, such as
Finds any line that includes
user *. The regular expression string
\x, followed by a hexadecimal value, specifies an individual character. In this example,
\x2a represents the asterisk character, which has a hexadecimal value of
Web Console and Syslog Viewer (Search Messages tab)
Regular expression search for syslog messages is not currently supported. Matching is only available on simple SQL string patterns, where
_ are used to indicate single, replaced characters and where
% are used to indicate zero characters or to delineate multiple characters, as indicated in the following examples:
IP Address filter:
192.168.74.*- IP addresses in range
192.168.74.1 - 192.168.74.255
192.168.74._) - IP addresses in range
192.168.74.1 - 192.168.74.9
%.168.74%) - IP addresses containing
*.74.25) - IP addresses ending with
Message Type filter:
orion%) - message type starts with "
message????- message type starts with "
message" plus any 4 symbols, like "
*orion*) - message type contains "
Message Pattern filter:
syslog message from 192.168.*- message starts with "
syslog message from 192.168."
*Server_ *messages containing the word "
Server" and any symbol before the space.
Syslog rules allow you to filter matching messages using a Regex pattern or simple SQL string patterns, provided the Use regular expressions option is enabled. Regular expressions may be used in syslog message filtering, as follows:
DNS Hostname pattern
.*domain.com$- DNS name ends with
^Orion.*- DNS name starts with
.*Orion.*- DNS name contains
Message Type Pattern
^[A,B,C]- message type starts with
^[0-9].*log$- message type starts with number value from
9and ends with
.*[^0-9]10.0.0.1[^0-9].*- message contains IP address
^Orion.*[^0-9]10.0.0.1[^0-9].*message starts with
Orionand contains IP address
.*" could be omitted at both the end and the beginning of the expression.