/
^[""]*<(?<alert_type>\d+)>(?<timestamp>.*\d+:\d+:\d+)\s(?<tenable_instance_hostname>[^""]+)\s(?<tenable_product_name>[^""]+)\[\d+\]:[\s""]*(?<tenable_internal_mtype>[^""]+)[""\s]*(?<tenable_internal_alertid>\d+)[""\s]*(?<ad_forest_name>[^""]+)[""\s]*(?<ad_domain_name>[^""]+)[""\s]*(?<ad_attack_name>[^""]+)[""\s]*(?<tenable_severity_level>[^""]+)[""\s]*(?<source_name>[^""]+)[""\s]*(?<source_ip>[^""]+)[""\s]*(?<destination_name>[^""]+)[""\s]*(?<destination_ip>[^""]+)[""]*\s(?<tenable_insertion_strings>.*?)$
/
gm