Parsing done for [symantec:ep:risk:file]
\,([^\,]+)\,IP Address:\s([^\,]+)\,Computer name:\s([^\,]+)\,Source:\s([^\,]+)\,Risk name:\s([^\,]+)\,Occurrences:([^\,]+)\,([^\,]+)\,\,Actual action:\s([^\,]+)\,Requested action:\s([^\,]+)\,Secondary action:\s([^\,]+)\,Event time:\s([^\,]+)\,Inserted:\s([^\,]+)\,End:\s([^\,]+)\,Last update time:\s([^\,]+)\,Domain:\s([^\,]+)\,Group:\s([^\,]+)\,Server:\s([^\,]+)\,User:\s([^\,]+)\,Source computer:([^\,]+)\,Source IP:([^\,]+)\,Disposition:\s([^\,]+)\,Download site:\s([^\,]+)\,Web domain:\s([^\,]+)\,Downloaded by:\s([^\,]+)\,Prevalence:\s([^\,]+)\,Confidence:\s([^\,]+)\,URL Tracking Status:\s([^\,]+)\,First Seen:\s([^\,]+)\,Sensitivity:([^\,]+)\,Permitted application reason:\s([^\,]+)\,Application hash:\s([^\,]+)\,Hash type:\s([^\,]+)\,Company name:\s([^\,]+)\,Application name:\s([^\,]+)\,Application version:\s([^\,]+)\,Application type:\s([^\,]+)\,File size (bytes):\s([^\,]+)\,Category set:\s([^\,]+)\,Category type:([^\,]+)\,Location:\s([^\,]+)\,Intensive Protection Level:\s([^\,]+)\,Certificate issuer:\s([^\,]+)\,Certificate signer:\s([^\,]+)\,Certificate thumbprint:\s([^\,]+)\,Signing timestamp:\s([^\,]+)\,Certificate serial number:\s([^\,]+)
... View more