Thank you for the reply Badger! Sorry for my late response
here is an event:
{
"_index": "network-2018.06.13",
"_type": "doc",
"_id": "f9eu-WMBqWuAu2Ip5NEe",
"_version": 1,
"_score": null,
"_source": {
"port": 43810,
"type": "syslog",
"raw_message": "1,2018/06/13 08:06:18,serialnum,SYSTEM,dhcp,0,2018/06/13 08:06:17,,lease-start,,0,0,general,informational,\"DHCP lease started ip 10.xxx.xxx.xxx --> mac - hostname iPhone, interface ethernet1/5\",6984574,0x8000000000000000,0,0,0,0,,PALOALTO",
"message": "<14>Jun 13 08:06:18 Panorama 1,2018/06/13 08:06:18,serialnum,SYSTEM,dhcp,0,2018/06/13 08:06:17,,lease-start,,0,0,general,informational,\"DHCP lease started ip 10.xxx.xxx.xxx --> mac - hostname iPhone, interface ethernet1/5\",6984574,0x8000000000000000,0,0,0,0,,PALOALTO",
"@version": "1",
"syslog_pri": "14",
"host": "Panorama",
"role": "api-hello-app",
"tags": [
"netsyslog",
"SYSTEM"
],
"hostname": "Panorama",
"@timestamp": "2018-06-13T15:06:18.422Z"
},
"fields": {
"@timestamp": [
"2018-06-13T15:06:18.422Z"
]
},
"sort": [
1528902378422
]
}