**Phase 1: Completed pre-decoding.
full event: 'Oct 6 10:36:04 2022-10-06 10: 36:04,350 sentinel - CEF:2|SentinelOne|Mgmt|Windows 10 Pro|rt=2022-10-06 10:35:55.658115|fileHash=01412235baf64c5b928252639369eea4e2ba5192|filePath=\Device\HarddiskVolume3\Users\my.user\Downloads\Alerta.exe|fileName=Alerta.exe|deviceAddress=18.198.190.203|deviceHostFqdn=
euce1-exclusive.sentinelone.net|deviceHostName=
euce1-exclusive.sentinelone.net|notificationScope=SITE|siteId=1358622531178348588|siteName=Group|accountId=1358622531169959977|accountName=ES \|\|ES-76\|\Security Services S.L.|vendor=SentinelOne|eventID=4003|eventDesc=New Suspicious threat detected - machine WRKO119|eventSeverity=1|originatorName=WRKO119|originatorVersion=21.7.5.1080|sourceAgentLastActivityTimestamp=2022-10-06 10:35:55.638991|sourceAgentRegisterTimestamp=2022-05-07 14:30:33.134606|sourceNetworkState=connected|sourceOsRevision=19044|sourceOsType=windows|sourceAgentUuid=6ed9d5783d56413f800a0138f34feb75|sourceFqdn=WRKO119.WORKGROUP|sourceThreatCount=2|sourceMgmtPrecievedAddress=92.184.80.14|sourceDnsDomain=WORKGROUP|sourceHostName=WRKO119|sourceUserName=|sourceUserId=|sourceAgentId=1415200390635609493|sourceGroupId=1372370298216691873|sourceGroupName=Security|sourceIpAddresses=['192.168.59.1', 'fe80::15c8:d6d:a7f:976b', '192.168.56.1', 'fe80::64a8:6a29:bcca:aacc', '192.168.63.1', 'fe80::dd9a:a2a:ae92:beb9', '172.28.176.1', 'fe80::44db:a5f5:ded8:d2c5', '192.168.1.102', 'fe80::2d84:6e27:fcad:f24c', '172.18.32.1', 'fe80::3529:ad88:f9ae:4a9f']|sourceMacAddresses=['0a:00:27:00:00:11', '0a:00:27:00:00:19', '0a:00:27:00:00:06', '00:15:5d:8a:79:3c', 'c2:21:b9:a2:1f:40', '00:15:5d:98:ab:8a']|threatClassification=None|threatClassificationSource=None|threatDetectingEngine=windows.preExecutionSuspicious|threatClassifier=STATIC|threatMitigationStatus=not_mitigated|threatConfidenceLevel=suspicious|threatMitigatedPreemptively=False|threatMitigationStatusLabel=suspicious|threatMitigationStatusID=3|threatCommandLineArguments=None|threatID=1525248211309748254|threatStoryline=E32635ECDC1E8118|threatDetectionTime=2022-10-06 10:35:55.658115|threatIndicatorsList=[29, 12]|threatProcessUser=GROUP\my.user|fileHashSha256=None|fileHashMd5=None|cat=MALWARE|activityID=1525248211443965987|activityType=4003'
timestamp: '(null)'
hostname: 'wazuhaoi-srv'
program_name: '(null)'
log: 'Oct 6 10:36:04 2022-10-06 10: 36:04,350 sentinel - CEF:2|SentinelOne|Mgmt|Windows 10 Pro|rt=2022-10-06 10:35:55.658115|fileHash=01412235baf64c5b928252639369eea4e2ba5192|filePath=\Device\HarddiskVolume3\Users\my.user\Downloads\Alerta.exe|fileName=Alerta.exe|deviceAddress=18.198.190.203|deviceHostFqdn=
euce1-exclusive.sentinelone.net|deviceHostName=
euce1-exclusive.sentinelone.net|notificationScope=SITE|siteId=1358622531178348588|siteName=Group|accountId=1358622531169959977|accountName=ES \|\|ES-76\|\Security Services S.L.|vendor=SentinelOne|eventID=4003|eventDesc=New Suspicious threat detected - machine WRKO119|eventSeverity=1|originatorName=WRKO119|originatorVersion=21.7.5.1080|sourceAgentLastActivityTimestamp=2022-10-06 10:35:55.638991|sourceAgentRegisterTimestamp=2022-05-07 14:30:33.134606|sourceNetworkState=connected|sourceOsRevision=19044|sourceOsType=windows|sourceAgentUuid=6ed9d5783d56413f800a0138f34feb75|sourceFqdn=WRKO119.WORKGROUP|sourceThreatCount=2|sourceMgmtPrecievedAddress=92.184.80.14|sourceDnsDomain=WORKGROUP|sourceHostName=WRKO119|sourceUserName=|sourceUserId=|sourceAgentId=1415200390635609493|sourceGroupId=1372370298216691873|sourceGroupName=Security|sourceIpAddresses=['192.168.59.1', 'fe80::15c8:d6d:a7f:976b', '192.168.56.1', 'fe80::64a8:6a29:bcca:aacc', '192.168.63.1', 'fe80::dd9a:a2a:ae92:beb9', '172.28.176.1', 'fe80::44db:a5f5:ded8:d2c5', '192.168.1.102', 'fe80::2d84:6e27:fcad:f24c', '172.18.32.1', 'fe80::3529:ad88:f9ae:4a9f']|sourceMacAddresses=['0a:00:27:00:00:11', '0a:00:27:00:00:19', '0a:00:27:00:00:06', '00:15:5d:8a:79:3c', 'c2:21:b9:a2:1f:40', '00:15:5d:98:ab:8a']|threatClassification=None|threatClassificationSource=None|threatDetectingEngine=windows.preExecutionSuspicious|threatClassifier=STATIC|threatMitigationStatus=not_mitigated|threatConfidenceLevel=suspicious|threatMitigatedPreemptively=False|threatMitigationStatusLabel=suspicious|threatMitigationStatusID=3|threatCommandLineArguments=None|threatID=1525248211309748254|threatStoryline=E32635ECDC1E8118|threatDetectionTime=2022-10-06 10:35:55.658115|threatIndicatorsList=[29, 12]|threatProcessUser=GROUP\my.user|fileHashSha256=None|fileHashMd5=None|cat=MALWARE|activityID=1525248211443965987|activityType=4003'
**Phase 2: Completed decoding.
decoder: 'sentinelone-custom'
filehash: '01412235baf64c5b928252639369eea4e2ba5192'
You can add as many decoders as you want to get the different field that you might need.
Please let me know if you need anything else, always glad to help.