Looks like a job for the kv filter. Use a grok filter to extract the timestamp and the loglevel (and perhaps the logger name) into discrete fields and stuff the rest of the log message into a field that you feed to a kv filter.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.