You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Zabbix中使用正则表达式提取事件日志指定片段

Zabbix事件日志正则提取问题

我正在Zabbix中监控Windows事件日志,已成功拉取完整日志内容,但需要用正则表达式提取其中的特定片段。

完整日志内容

An account failed to log on.

Subject:
    Security ID:        NULL SID
    Account Name:       -
    Account Domain:     -
    Logon ID:       0x0

Logon Type:         3

Account For Which Logon Failed:
    Security ID:        NULL SID
    Account Name:       xxxxxxx
    Account Domain:     xxxxxxx

Failure Information:
    Failure Reason:     Unknown user name or bad password.
    Status:         0xC000006D
    Sub Status:     0xC000006A

Process Information:
    Caller Process ID:  0x0
    Caller Process Name:    -

Network Information:
    Workstation Name:   SSAPL1
    Source Network Address: 0.0.0.0
    Source Port:        40410

Detailed Authentication Information:
    Logon Process:      NtLmSsp 
    Authentication Package: NTLM
    Transited Services: -
    Package Name (NTLM only):   -
    Key Length:     0

This event is generated when a logon request fails. It is generated on the computer where access was attempted.

The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).

The Process Information fields indicate which account and process on the system requested the logon.

The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
    - Transited services indicate which intermediate services have participated in this logon request.
    - Package name indicates which sub-protocol was used among the NTLM protocols.
    - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.

需要提取的目标片段

Subject:
    Security ID:        NULL SID
    Account Name:       -
    Account Domain:     -
    Logon ID:       0x0

Logon Type:         3

Account For Which Logon Failed:
    Security ID:        NULL SID
    Account Name:       xxxxxxx
    Account Domain:     xxxxxxx

Failure Information:
    Failure Reason:     Unknown user name or bad password.
    Status:         0xC000006D
    Sub Status:     0xC000006A

Process Information:
    Caller Process ID:  0x0
    Caller Process Name:    -

Network Information:
    Workstation Name:   SSAPL1
    Source Network Address: 0.0.0.0
    Source Port:        40410

Detailed Authentication Information:
    Logon Process:      NtLmSsp 
    Authentication Package: NTLM
    Transited Services: -
    Package Name (NTLM only):   -
    Key Length:     0

尝试过的无效正则

)
^
  (?:
    \s\w\w\w
    (?:
      \w\w
      (?:
        \w
        (?:
          \w\s\w\w\w\w
          (?:
            \w\w:\s\s
            (?:
              \w\w\w\w\w\w\w\s\w\w\w\w\s\w\w\w\w\s\w\w\s\w\w\w\s\w\w\w\w\w\w\w\w
              \.
              |
              \-
            )
            |
            :\s\s
            \-
          )
          |
          \s\w\w\w\w\w\w\w\s\w\w\w\w\w\w\w:\s\w\w\.\w\.\w\.\w\w
          |
          \w
          (?:
            \w\w\w\w\w\w\w\s\w\w\w\w\w\w\w
            :\s
            |
            \s\w\w\w\w\w\w
            :\s\s\w\w\w\w
            \.
          )\w\w\w\w
          |
          \w\s\w\w\w\w:\s\s\w\w\w\w\w\w\w\w\w\w\w\w\w
          |

      :\s\s\s\w
    )
  )
$

解决方案

你之前的正则过于复杂且逻辑混乱,完全没必要这么写。根据日志结构,目标片段是从Subject:开始,到说明性文字This event is generated...之前的内容,用以下简洁正则即可实现:

方案1:匹配到固定结尾行

(?ms)^Subject:.*?Key Length:\s+0$
  • (?ms):同时开启多行模式(m)和单行模式(s),确保跨行匹配且.能识别换行符
  • ^Subject::定位目标片段的起始行
  • .*?:非贪婪匹配任意内容,避免过度匹配到后面的说明文字
  • Key Length:\s+0$:定位目标片段的结尾行

方案2:匹配到说明文字前(更通用)

如果日志中Key Length的值可能变化,用这个正则更稳定:

(?ms)^Subject:.*?(?=\n\nThis event is generated)
  • (?=\n\nThis event is generated):正向预查,匹配到两个换行加说明文字开头的位置就停止,不管结尾行内容如何都能准确截取目标片段

在Zabbix中使用时,直接将上述正则填入对应字段即可完成提取。

内容的提问来源于stack exchange,提问作者mikael

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 02:50:24