Need some help with a log regex
Posted: 11 Nov 2024, 23:58
Can someone provide a regex that handles this line in /var/log/secure? I tried a couple of things, and don't seem to get it, even trying to copy and adapt one that's already there. Here's the line:
Nov 11 13:00:01 boston systemd[2322963]: pam_unix(systemd-user:session): session opened for user root(uid=0) by root(uid=0)
I'm getting these in LFD Log Scanner reports
Nov 11 13:00:01 boston systemd[2322963]: pam_unix(systemd-user:session): session opened for user root(uid=0) by root(uid=0)
I'm getting these in LFD Log Scanner reports