AnsweredAssumed Answered

Logmon: needed advice regarding regex

Question asked by AtosMonitoring on Apr 26, 2017
Latest reply on May 3, 2017 by Garin

Hi there,

 

I need some help creating a special Match Expression within the logmon probe (I am very new in regular expressions):

 

I'm trying to parse a reg file (Windows registry export) for a string. If the the string is NOT in the file, an alarm should appear.

For example: The content of the reg file could be like

This is just a registry file example
--------------------------------------

[HKLM\Software\Microsoft\DirectX]
"Version"="4.09.000.123.12229

"MyKey" = "22222222"

 

I created the following regular expression (with help of http://regexr.com/): /^((?!MyKey)[\s\S])*.$/

 

On the mentioned website the regular expression works fine - Removing one character from MyKey => match

But if I enter the expression in the "Match Expression" field and restart the probe, no alarm shows up.

 

 Do anyone has an idea, why no alarm comes up?

 

Hope, someone has an idea/hint ...

Thanks

 

 

Outcomes