Extract fields from syslog "message" part for visualization in Kibana

Correct. In that case go to the line in the config that sets field_split and change the space between the double quotes to be a tab.