<div>Nope, no luck yet. Still blanks being spit out. </div><div><br></div><div>Here&#39;s the exact extract of the pattern matching and the log:</div><div><br></div><div>Pattern String</div><div>---------------------------</div>
<div><br></div><div><div>@ESTRING:user::@ Security Microsoft Windows security auditing.: [Success Audit] A computer account was changed.    Subject:   Security ID:  S-1-5-7   Account Name:  ANONYMOUS LOGON   Account Domain:  NT AUTHORITY   Logon ID:  0x3e6    Computer Account That Was Changed:   Security ID:  @ESTRING::  @Account Name:   @ESTRING:ACC_NAME: @   Account Domain:  WW002    Changed Attributes:   SAM Account Name: -   Display Name:  -   User Principal Name: -   Home Directory:  -   Home Drive:  -   Script Path:  -   Profile Path:  -   User Workstations: -   Password Last Set: @ESTRING:: @@ESTRING:: @   Account Expires:  -   Primary Group ID: -   AllowedToDelegateTo: -   Old UAC Value:  -   New UAC Value:  -   User Account Control: -   User Parameters: -   SID History:  -   Logon Hours:  -   DNS Host Name:  -   Service Principal Names: -    Additional Information:   Privileges:  - (EventID 4742)</div>
</div><div><br></div><div>Log</div><div>------------------</div><div><br></div><div><div>Dec 22 03:38:32 <a href="http://Server.zoom11.test.net">Server.zoom11.test.net</a> Microsoft_Windows_security_auditing.[5784]: : Security Microsoft Windows security auditing.: [Success Audit] A computer account was changed.    Subject:   Security ID:  S-1-5-7   Account Name:  ANONYMOUS LOGON   Account Domain:  NT AUTHORITY   Logon ID:  0x3e6    Computer Account That Was Changed:   Security ID:  S-1-5-21-776561741-789336058-725345543-305444   Account Name:  User1$   Account Domain:  TEST    Changed Attributes:   SAM Account Name: -   Display Name:  -   User Principal Name: -   Home Directory:  -   Home Drive:  -   Script Path:  -   Profile Path:  -   User Workstations: -   Password Last Set: 12/22/2011 3:38:32 AM   Account Expires:  -   Primary Group ID: -   AllowedToDelegateTo: -   Old UAC Value:  -   New UAC Value:  -   User Account Control: -   User Parameters: -   SID History:  -   Logon Hours:  -   DNS Host Name:  -   Service Principal Names: -    Additional Information:   Privileges:  - (EventID 4742)</div>
</div><div><br></div><div><br></div><div><br></div><br><br><div class="gmail_quote">2011/12/22 Fekete Róbert <span dir="ltr">&lt;<a href="mailto:frobert@balabit.hu">frobert@balabit.hu</a>&gt;</span><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im"><br>
On Wednesday, December 21, 2011 16:22 CET, Anup Shetty &lt;<a href="mailto:anupdshetty@gmail.com">anupdshetty@gmail.com</a>&gt; wrote:<br>
<br>
&gt; I am trying to match the pattern for DC logs and here is my XML format<br>
&gt;<br>
&gt; Here&#39;s the patterndb.xml file at /opt/syslog-ng/var/patterndb.xml&quot;<br>
&gt; ---------------------------------------<br>
&gt; &lt;?xml version=&#39;1.0&#39; encoding=&#39;UTF-8&#39;?&gt;<br>
&gt; &lt;patterndb version=&#39;3&#39; pub_date=&#39;2011-12-21&#39;&gt;<br>
&gt; &lt;ruleset id=&#39;90c9b341f4e3d63c5ed8b29950491bf8&#39; name=&#39;Domain Ctrls&#39;&gt;<br>
&gt; &lt;rules&gt;<br>
&gt;         &lt;rule provider=&#39;localtest&#39; id=&#39;012c230f236d6a3f761ba956e7dff26a&#39;<br>
&gt; class=&#39;system&#39;&gt;<br>
&gt;         &lt;patterns&gt;<br>
&gt;                         &lt;pattern&gt;<br>
&gt; @ESTRING:user::@ Security Microsoft Windows security auditing.: [Success<br>
&gt; Audit] A computer account was changed.    Subject:   Security ID:  S-1-5-7<br>
&gt;   Account Name:  ANONYMOUS LOGON   Account Domain:  NT AUTHORITY   Logon<br>
&gt; ID:  0x3e6    Computer Account That Was Changed:   Security ID:  @ESTRING::<br>
</div>&gt;  @Account Name:   @ESTRING:*ACC_NAME*: @   Account Domain:  testdomain<br>
<div><div></div><div class="h5">&gt;  Changed Attributes:   SAM Account Name: -   Display Name:  -   User<br>
&gt; Principal Name: -   Home Directory:  -   Home Drive:  -   Script Path:  -<br>
&gt; Profile Path:  -   User Workstations: -   Password Last Set: @ESTRING::<br>
&gt; @@ESTRING:: @   Account Expires:  -   Primary Group ID: -<br>
&gt; AllowedToDelegateTo: -   Old UAC Value:  -   New UAC Value:  -   User<br>
&gt; Account Control: -   User Parameters: -   SID History:  -   Logon Hours:  -<br>
&gt;   DNS Host Name:  -   Service Principal Names: -    Additional Information:<br>
&gt;   Privileges:  - (EventID 4742)<br>
&gt; &lt;/pattern&gt;<br>
&gt;                     &lt;/patterns&gt;<br>
&gt;<br>
&gt; &lt;/rule&gt;<br>
&gt; &lt;/rules&gt;<br>
&gt; &lt;/ruleset&gt;<br>
&gt; &lt;/patterndb&gt;<br>
&gt;<br>
&gt; ---------------------------------------<br>
&gt; Here&#39;s the syslog-ng conf extract:<br>
&gt; ---------------------------------------<br>
&gt; parser pattern_db {<br>
&gt;             db_parser(<br>
&gt;                 file(&quot;/opt/syslog-ng/var/patterndb.xml&quot;)<br>
&gt;             );<br>
&gt;             };<br>
&gt; destination patt_d{<br>
&gt; file(&quot;/data/test/${R_YEAR}/${R_MONTH}/${R_DAY}/Domain_Ctrl__${SOURCEIP}_${R_YEAR}_${R_MONTH}_${R_DAY}.log&quot;<br>
&gt; owner(&quot;test&quot;)<br>
&gt;                 group(&quot;test&quot;)<br>
&gt;                 perm(0660)<br>
&gt;                 dir-owner(&quot;test&quot;)<br>
&gt;                 dir-group(&quot;test&quot;)<br>
&gt;                 dir-perm(0770)<br>
</div></div>&gt; template(&quot;$*ACC_NAME*\n $MSG\n&quot;)<br>
&gt;         );<br>
&gt; };<br>
&gt;<br>
&gt; ---------------------------------<br>
&gt;<br>
&gt; but the *ACC_NAME* returns blank, although the log contains that field.<br>
Hi,<br>
<br>
Try<br>
template(&quot;${ACC_NAME}\n $MSG\n&quot;)<br>
<br>
HTH,<br>
<br>
Robert<br>
<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt; Thanks<br>
&gt; Anup<br>
<br>
<br>
<br>
<br>
<br>
<br>
______________________________________________________________________________<br>
Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br>
Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br>
FAQ: <a href="http://www.balabit.com/wiki/syslog-ng-faq" target="_blank">http://www.balabit.com/wiki/syslog-ng-faq</a><br>
<br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div>Thanks and regards,<br>Anup</div><br>