<decoder name="unifi_02">
<type>syslog</type>
<prematch type="pcre2">UAP-AC-Pro-Gen2</prematch>
</decoder>
<decoder name="unifi_log2">
<prematch type="pcre2">UAP-AC-Pro-Gen2</prematch>
<regex type="pcre2">(.*?)\s(UAP.*?)\s(.*?)\,.*?\s(.*?)\:\s(.*?)\:.*?\s.*?\s(.*?)\s(.*?)\:\s(.*)</regex>
<order>AP_Date, AP_type, AP_MAC, AP_service, AP_interface, AP_client_MAC, AP_standard_type, AP_message</order>
</decoder>
Here you are the complete decoding:
**Phase 1: Completed pre-decoding. full event: 'Jan 17 11:07:00 UAP-AC-Pro-Gen2 802aa8967335,UAP-AC-Pro-Gen2-6.5.62+14788: hostapd[1678]: ath4: STA 7e:70:94:96:a0:08 MLME: MLME-DEAUTHENTICATE.indication(7e:70:94:96:a0:08, 15)' timestamp: 'Jan 17 11:07:00' hostname: 'UAP-AC-Pro-Gen2'**Phase 2: Completed decoding. name: 'unifi_02'
There aren´t fields in the test.
Could someone help us?
Thanks you.
If you have any questions, please let me know.
Best,