Grok help with cisco firepower 2130

I would use dissect to parse the first 2 fields, then dissect to parse the rest of the line. See this for an example.