Where to start?

hey there! another noob here, but I think I can help on that! I think the way to go would be creating extractors, kinda like I did with Symantec Endpoint Protection Manager logs: