Hi Luciano,
Thanks very much for taking the time to reply.
Your explanation makes it more clear on how the pre-decoder works, and it makes more sense to me now.
I will take some time to experiment with the "out_format" option, as you suggested, and I think I will be good to go with that.
I still have a question related to that though:
In my previous tests, I also tried to use "hostname" instead of "program_name", as it is correctly extracted by the pre-decoder, and which would be a perfect solution to create decoders and rules, but for some reason it didn't work either.
So is there a reason for that, and can we only use "program_name" and nothing else for this type of logs?
Thanks.