<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<ns2:device-extension xmlns:ns2="event_parsing/device_extension">
    <pattern id="DestinationIp-Pattern-1">Destination=(.? )</pattern>
    <pattern id="DestinationPort-Pattern-1">AppName=(.*)(?=AppID=)</pattern>
    <pattern id="EventCategory-Pattern-1">^(?:[^|]*\|){5}([^|]*)</pattern>
    <pattern id="EventName-Pattern-1">^(?:[^|]*\|){5}([^|]*)</pattern>
    <pattern id="HostName-Pattern-1">DeviceName=(.*Event=)</pattern>
    <pattern id="DeviceTime-Pattern-1">Timestamp=(.*Z)</pattern>
    <pattern id="SourceIp-Pattern-1">DeviceName=(.*)(?=Event=)</pattern>
    <pattern id="UserName-Pattern-1">DeviceName=(.*)(?=Event=)</pattern>
    <match-group device-type-id-override="367" order="1">
        <matcher order="1" enable-substitutions="true" capture-group="\1" pattern-id="DestinationIp-Pattern-1" field="DestinationIp"/>
        <matcher order="1" capture-group="0" pattern-id="DestinationPort-Pattern-1" field="DestinationPort"/>
        <matcher order="1" enable-substitutions="true" capture-group="\1" pattern-id="EventCategory-Pattern-1" field="EventCategory"/>
        <matcher order="1" enable-substitutions="true" capture-group="\1" pattern-id="EventName-Pattern-1" field="EventName"/>
        <matcher order="1" enable-substitutions="true" capture-group="\1" pattern-id="HostName-Pattern-1" field="HostName"/>
        <matcher ext-data="yyyy-MM-dd'T'HH:mm:ss'Z'" order="1" enable-substitutions="true" capture-group="\1" pattern-id="DeviceTime-Pattern-1" field="DeviceTime"/>
        <matcher order="1" enable-substitutions="true" capture-group="\1" pattern-id="SourceIp-Pattern-1" field="SourceIp"/>
        <matcher order="1" enable-substitutions="true" capture-group="\1" pattern-id="UserName-Pattern-1" field="UserName"/>
        <event-match-multiple force-qidmap-lookup-on-fixup="true" send-identity="UseDSMResults" pattern-id="EventName-Pattern-1"/>
    </match-group>
</ns2:device-extension>
