I am working on migrating from Splunk to ELK for my Palo Alto Networks firewall logs using the pre-built processor in Filebeat. The pipeline is Syslog > Filebeat > Elastic. The PANW logs contain two separate fields for URL Category: one with just a single value (which is extracted in the stock Filebeat input.yml as a string) and another one which contains a quoted string which is a list of comma separated categories (e.g. "music, streaming-services,low-risk"). I would like to extract this list into a field with multiple values (similar to how the Tags field can have multiple values). Is it possible to do this in Filebeat?