# Regex, logstash and passwords

**URL:** <https://discuss.elastic.co/t/regex-logstash-and-passwords/112322>\
**Category:** Logstash\
**Created:** [December 18, 2017, 11:40pm UTC](https://discuss.elastic.co/t/regex-logstash-and-passwords/112322 "2017-12-18T23:40:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 18, 2017, 11:40pm UTC](https://discuss.elastic.co/t/regex-logstash-and-passwords/112322/1 "2017-12-18T23:40:09Z")

</div>

So I'm looking for a way to detect when someone enters their password and then subst out the password for hashes. The 1.1.1.8 is an example, it could be any ip address.

From this I want to detect if there is a password there

net use I: \1.1.1.8\E$ /user:domain\username password /persistent:yes

Look behind, almost seems to have it but I can't get it to stop after the space after username...

(?\<=/user:)(.\*)(?\<=\s)

net use I: \1.1.1.8\E$ /user:d **omain\username password** /persistent:yes

when I need it to get -

net use I: \1.1.1.8\E$ /user:domain\username **password** /persistent:yes

[https://regexr.com/3i6va](https://regexr.com/3i6va)

... it would be something like this to gsub the password out and replace with ###

filter {  
if [event\_id] == 4688 {  
mutate {  
gsub =\> ["[event\_data][CommandLine]", "(?\<=/user:)(.\*)(?\<=\s)",  
"########" ]  
}  
}  
}

...I think I can get the gsub to work but for the life of me I can't get that regex to work.

Thanks!

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 3, 2018, 3:07pm UTC](https://discuss.elastic.co/t/regex-logstash-and-passwords/112322/2 "2018-01-03T15:07:04Z")

</div>

Perhaps `(?:\/user:\w+\s)(\S+)(?:\s)`

[https://regexr.com/3inrv](https://regexr.com/3inrv)

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [January 5, 2018, 4:27pm UTC](https://discuss.elastic.co/t/regex-logstash-and-passwords/112322/3 "2018-01-05T16:27:56Z")

</div>

Hey @guyboertje,

Man closer but that seems to hit the userame as well - I mean I could use that... but I really want to get that regex to just grab the password...  
/user:domainusername password  
wanted to see if it could grab just the password no /user:domainusername

I know I'm stubborn 🙂

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 5, 2018, 5:41pm UTC](https://discuss.elastic.co/t/regex-logstash-and-passwords/112322/4 "2018-01-05T17:41:31Z")

</div>

Ahh. Now, this works in Ruby 2.4.0 `(?:\/user:\w+\s)\K(\S+)(?=\s)` 🙂 but it does not in JRuby 9.1.13.0 ☹

It does work with JRuby 9.1.15.0 🙂 but LS is will not ship with that version for a while because other bugs ☹

I can't think of a way to do what you want differently.

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [January 9, 2018, 3:17pm UTC](https://discuss.elastic.co/t/regex-logstash-and-passwords/112322/5 "2018-01-09T15:17:19Z")

</div>

I appreciate the effort @guyboertje!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2018, 3:17pm UTC](https://discuss.elastic.co/t/regex-logstash-and-passwords/112322/6 "2018-02-06T15:17:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
