Skip to content

Document ossec-regex -p for PCRE2 patterns - #371

Merged
atomicturtle merged 1 commit into
ossec:masterfrom
atomicturtle:docs/1845-ossec-regex-pcre2
Oct 7, 2026
Merged

atomicturtle merged 1 commit into
ossec:masterfrom
atomicturtle:docs/1845-ossec-regex-pcre2

Conversation

@atomicturtle

@atomicturtle atomicturtle commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Document ossec-regex -p / --pcre2, which tests a pattern as PCRE2 with the same flags as a <pcre2> rule.
  • Note that the default mode is still legacy OSSEC regex and match syntax, so ., *, and { are rewritten before matching.
  • Point the PCRE2 syntax page at ossec-regex -p.

Code: ossec/ossec-hids#2320

Test plan

  • Review docs/programs/ossec-regex.rst against ossec-regex -h and a -p run
  • Confirm the :ref: links to regex and ossec-regex-convert resolve

Without -p the tool still speaks legacy OSSEC regex, which is what made
PCRE2 patterns such as (.*\.){7,} look like they did not match.
@atomicturtle
atomicturtle merged commit 5b1d9c5 into ossec:master Oct 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant