For me these log messages contain a space at the end of the line (snmpd version 5.4.3~dfsg-2). So this rule may need an additional " ?" or " *" at the end to work for all cases: ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ snmpd\[[0-9]+\]: Connection from UDP: \[[.0-9]{7,15}\]:[0-9]{4,5}->\[[.0-9]{7,15}\] ?$