Extract parameters from a message

grok is not the right tool for this. Use a kv filter

kv { field_split => "&" include_keys => [ "Tenant" ] }

The include_keys option is optional, by default it will extract every key/value pair. There is also an exclude_keys option.

1 Like