hello, I need help in extracting the fields that come in the "message" field, in case all the fields need to be extracted, can anyone help?
here's the field:
"message": "Apr 14 16:11:36 tutorial2022-1 sshd[8454]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=xx.xxx.xxx.xx user=root"