use strict;
my $str = '06 12 2017 22:31:35 1.2.1.1 <LOC0:INFO> 1 2017-06-12T22:31:35+02:00 dedusfw EFW - - - CONN: prio=1 id=00600001 rev=1 event=conn_open rule=local_to_nds_dc conn=open connipproto=TCP connrecvif=GESW_vlan2 connsrcip=1.1.1.7 connsrcport=51435 conndestif=G1_vlan253 conndestip=4.1.1.1 conndestport=443
CONN\\:.*?prio=(?<severity>\\d)\\s+id=(?<vmid>\\d+).*?action=(?<action>\\w+).*?rule=(?<tag1>.*?)\\s+recvif=(?<tag2>.*?)\\s+srcip=<sip>';
my $regex = qr/CONN\:.*?prio=(?<severity>\d)\s+id=(?<vmid>\d+).*?event=(?<tag1>\w+)\s+rule=(?<tag2>\w+)\s+conn=(?<tag3>\w+)\s+connipproto=(?<protname>\w+)\s+connrecvif=(?<dinterface>\w+)\s+connsrcip=(?<sip>(\d{1,3}\.){3}\d{1,3})\s+connsrcport=(?<sport>\d+).*?conndestip=(?<dip>(\d{1,3}\.){3}\d{1,3})\s+conndestport=(?<dport>\d+)/p;
if ( $str =~ /$regex/g ) {
print "Whole match is ${^MATCH} and its start/end positions can be obtained via \$-[0] and \$+[0]\n";
# print "Capture Group 1 is $1 and its start/end positions can be obtained via \$-[1] and \$+[1]\n";
# print "Capture Group 2 is $2 ... and so on\n";
}
# ${^POSTMATCH} and ${^PREMATCH} are also available with the use of '/p'
# Named capture groups can be called via $+{name}
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Perl, please visit: http://perldoc.perl.org/perlre.html