Description
Hello,
I have logs (from trendmicro console) in the following format (beside from the prefix)
Key<space...="" Key<space...=""
Unfortunately the key-value parser does not support spaces in they key and value markings via quotations.
Do I miss something, or is it possible to extend the key-value parser for this format?
Here a raw event:
<66>Mar 1 02:43:31 Hostname TMCM: SLF_INCIDENT_EVT_VIRUS_FOUND_QUARANTINE_SUCCESS Security product="ScanMail for Microsoft Exchange" Security product node="HE105647" Security product IP="1.2.3.4" Event time="06.03.2018 01:36:41 (UTC)" Virus="TSPY_HPLOKI.SM1" Infected file="PLS QUOTE PO # BD007362.zip" File path="SMTP" Action taken="Quarantine" Result="Quarantine successfully" Infection destination="[email protected];" Infection destination IP="1.2.3.4" Infection source="[email protected];" Infection source IP="" Destination IP="" Source IP="" Domain="internal.dom" ScanMethod="Real-time Scan" User="N/A" Managing server entity="Server" Event time (local)="01.03.2014 02:36:41"