Syslog - logs contain dynamic fields(parameters) based on event type, how to index?

I would use dissect to parse off the start of the message, then a kv filter. Something like this.