Regular Expression doesn't work


(Haythem Arfaoui) #1

Hello everyone,

I have a old regex query that doesn't work for me :

> C:\\Windows\\SYSTEM32\\ntdll\.dll\+[a-zA-Z0-9]{1,}\|C:\\Windows\\system32\\KERNELBASE\.dll\+[a-zA-Z0-9]{1,}\|UNKNOWN\([a-zA-Z0-9]{16}\)

and you can find in the picture below that i have after the name of the dll file a random characters so i need a regular expression to match the query

I have both Kibana and Elasticsearch version 6.6.1