diff --git a/parsers/community/cisco_ise_logs-latest/cisco_ise_logs.conf b/parsers/community/cisco_ise_logs-latest/cisco_ise_logs.conf index cba71fe..b9148ee 100644 --- a/parsers/community/cisco_ise_logs-latest/cisco_ise_logs.conf +++ b/parsers/community/cisco_ise_logs-latest/cisco_ise_logs.conf @@ -72,6 +72,11 @@ "dataSource.vendor": "Cisco" }, "format": "$timestamp=timestamp$ $hostname$ CISE_Administrator $log_id$,$log_id2$,$severity$,$category$,Admin-Name=$admin_user$,Admin-Session-Id=$session_id$,Object-Name=$object_name$,Change-Type=$change_type$,Object-Type=$object_type$" + }, + { + format: ".*\"$_$\": \"$_$\"" + repeat: true + rewrites: [{input: "EventTimestamp", output: "timestamp", match: ".*", replace: "$0"}] } ] -} \ No newline at end of file +}