And try this! http://grokconstructor.appspot.com/
I came up with that in 1 min. You can use the mutate filter to remove fields
%{CISCOTIMESTAMP}%{SPACE}%{NOTSPACE}%{CRON_ACTION}%{NOTSPACE}%{SPACE}%{NOTSPACE}%{CRON_ACTION}%{GREEDYDATA:your_field}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.