Dear All,
I tried to forward some log to ELK from a device. I find all event merge into one message. May I know is it possible to separate into different event? here's the log example. Thanks
<51>May 16 10:10:35 xp SYServer: abc,,Allowed,C:\Program Files\SY\SY\38\Bin\ccSvcHst.exe,,Begin: 2018-05-16 10:08:54,End: 2018-05-16 10:08:54,Rule: ,3780,C:\PROGRAM FILES\ENTERPRISE\BES\BES.EXE,0,,C:\Program Files\SY\SY \38\Bin\ccSvcHst.exe,User: SYSTEM,Domain: ,Action Type: 10,File size (bytes): ,Device ID:
<51>May 16 10:10:35 XP SYServer: avc,,Allowed,C:\Program Files\SY\SY\38\Bin\ccSvcHst.exe,,Begin: 2018-05-16 09:45:36,End: 2018-05-16 09:45:36,Rule: ,3888,C:\PROGRAM FILES\ENTERPRISE\BES\BES.EXE,0,,C:\Program Files\SY\SY\38\Bin\ccSvcHst.exe,User: SYSTEM,Domain: ,Action Type: 10,File size (bytes): ,Device ID: