2016-04-15 37 views
0

請在下面找到,我從系統日誌攔截在水槽與系統日誌數據

< 159> 4月15日17時27分31秒192.168.100.40 CEF接收樣本日誌消息:0 | Websense的|安全| 7.8.1 | 68 |允許交易| 1 | act =允許的app = http dvc = 192.168.100.40 dst = 221.135.111.120 dhost = img-d01.moneycontrol.co.in dpt = 80 src = 172.16.237.89 spt = 55016 suser = LDAP://172.17.251.11 OU \ =用戶OU \ = Migrated,DC \ = abc,DC \ = com/Sourabh Jain destinationTranslatedPort = 38419 rt = 1460721451000 in = 496 out = 6999 requestMethod = GET requestClientApplication = Mozilla/5.0(Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0 reason = - cs1Label =策略cs1 =角色-8 **默認cs2Label = DynCat cs2 = 0 cs3Label = ContentType cs3 = image/jpeg cn1Label = DispositionCode cn1 = 1048 cn2Label = ScanDuration cn2 = 3請求= http://img-d01.moneycontrol.co.in/news_html_files/wealth-experts/abhim1132661059.jpg

如果您是觀察者,則數據中有關鍵值對。有沒有辦法,我可以提取值並存儲數據。我不能使用空格作爲分隔符,因爲密鑰對中的某些值包含空格 例如: suser = LDAP://172.17.251.11 OU \ = Users,OU \ = Migrated,DC \ = abc,DC \ = COM/Sourabh小號耆那

還有 「Sourabh小號耆那」 之間的空間

回答

0

能夠使用OR運算符來解決它。

(的suser = - | =的suser LDAP:// {1150} /)

+0

也注意到有一個開放源碼的CEF水槽下沉 https://github.com/srotya/cef –