Syslog input message cutting


Having issue with syslog input.

Sending syslog events from F5 to logstash with http payload data.
Payload field can be with xml data
http_payload="<?xml version='1.0' encoding='UTF-8'?>...
Logstash parsing syslog event with http_payload field to several separate fields http_payload , encoding and many others when there are space before a word and '=' after.

Can it be escaped?

