We have recently integrated TrendMicro web proxy device (version 6.5-SP2_Build_Linux_1731) with the SA. There's a specific filed which we notice in the row log "tk_size" which provides information about data transfer done in the particular session.
On the SA however, this field gets merged in "msg" section and support asked us to create the custom parser to accommodate the requirement.
While opening the log on ESI tool, I could notice that fld30 has been assigned to tk_size field already (PFA). Is there a way to call this meta "fld30" to investigation tab?
Any help much appreciated!!