$re = '/Audit (?P<audit_outcome>(Success|Failure)),(?P<log_date>.*)\s+(?P<log_time>.*),Microsoft-Windows-Security-Auditing,(?P<event_id>\d+),(?P<category>.*),(?P<event_message>.*)\s+(?P<audit_message>.*)/';
$str = 'Audit Success,08/03/2017 18:57:56,Microsoft-Windows-Security-Auditing,4608,Security State Change,"Windows is starting up.
This event is logged when LSASS.EXE starts and the auditing subsystem is initialized."';
preg_match_all($re, $str, $matches, PREG_SET_ORDER, 0);
// Print the entire match result
var_dump($matches);
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for PHP, please visit: http://php.net/manual/en/ref.pcre.php