Correct parsing Syslog message to json

I suggest using dissect to parse the prefix and then using a json filter to parse the rest. Something similar to this (except that uses kv rather than json).