I’m looking for a suggestion to decode message which come in form of key=ip-adress key=value key=timestamp key=“value”:
time=15:24:30 devname=NAME-1 devid=SD230N3G17966 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=001.002.003.004 srcport=55230 srcintf="wan1" dstip=008.009.010.011 dstport=445 dstintf="wan1" poluuid=ef0f1e78-84c6-99a739745c6b sessionid=81335928 proto=6 action=deny policyid=3 policytype=policy dstcountry="Germany" srccountry="Brazil" trandisp=noop service="SMB" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel=high
I tried to extract it using the key=value extractor as suggested in the manual. But it seems like this is not working with the " special character.
So I thought i just remove all the " from the message via an regex and replace extractor and afterwards extract the values via the k=v extractor.
But now I’m stuck on what to enter in the “replace” field. Just entering nothing (what I want in the end) is not working.
Is this even the right way to do it?
Any help is much appreciated!