These are coming from windows event logs. Some of the fields are in name value pairs and extract on their own but last 4 fields are the ones I need expressions for. Here is example of entire message: 10/27/2021 02:39:17 PM LogName=Application EventCode=16117 EventType=0 ComputerName=XXXXXXXXX002.xxxx.com User=NOT_TRANSLATED Sid=S-1-5-21-114000000-41296648-3127784425-637889 SidType=0 SourceName=AdminSvc Type=Information RecordNumber=1502524 Keywords=Audit Success, Classic TaskCategory=SetInfo OpCode=None Message=Action SetInfo ObjectType Computer AssistantAdmin xxxx\xxxxx Target xxxxx\xxxx-xxxx$ Domain Controller xxxxxx06 AccountDisabled
... View more