2024-06-07T00:00:03.375203+00:00 Fri Jun 7 00:00:03 2024 User Activity zpa-lss: ,Softeon,WBxjU8TwGSuDIqeH7E1A,WBxjU8TwGSuDIqeH7E1A,accdi9AfJVPM4/RDp+n/,BRK_MT_SETUP_FAIL_SAML_EXPIRED,close,6,0, rando...@sliftean.com,443,50.37.219.126,192.145.29.49,12.899600,80.220900,IN,AP-IN-2637,0,0,0,,0,kspuat.softeon.com,AWS-us-east-2-VPC1-KSP-AppAccess,AWS-us-east-2-VPC1-KSP-SegmentGroup,0,,443,0,0,2024-06-07T00:00:03.195Z,2024-06-07T00:00:03.195Z,,,,,,,,,,,,,0,0,0,0,0,0,0,0,Softeon Azure AD,0,Coimi,0,0
This is my syntax.
/var/ossec/etc/decoders# cat zpa-lss_decoder.xml
<decoder name="zpa-lss_decoder">
<program_name>zscaler</program_name>
<prematch>^\d\d\d\d-\d\d-\d\dT\d\d:\d\d:\d\d\.\d\d\d\d\d\d+\d\d:\d\d \w\w\w \w\w\w \d \d\d:\d\d:\d\d \d\d\d\d User Activity zpa=lss:\s</prematch>
</decoder>
lmk where I am going wrong