下面是我需要编写正则表达式来捕获主机名“ Renju123 ”的 DNS 示例日志。两个样本的日志格式结构几乎没有什么不同。
日志示例如下:
"2018-12-12 13:25:30","Renju, Jacob,M(renjutest)","Renju, Jacob, M (rtest),Renju123,Default Site,Test/firewall","10.221.5.136", "XXX.XXX.XXX.XXX","允许","16 (A)","NOERROR","1XX.1X.1XX.1XX.Test.com.","计算机安全"
"2018-12-12 13:09:55","rtest","Renju123,Default Site,Renju Renju/Renju","10.250.33.85","XXX.XXX.XXX.XXX","允许"," 12 (PTR)","NOERROR","1XX.1X.1XX.1XX.Test.com.","软件/技术"
我使用的正则表达式仅捕获第一个日志主机名
(?P(?<=),).*?(?=,.?Default))链接在这里
但我想要一个正则表达式从两个示例日志中捕获主机名(Renju123)