regex to parse space separated log message from splunk
test string
ugi=flink ip=172.18.214.55 cmd=source:172.18.214.55 alter_table: hive.net_seed.netdebugnetworkconnectionstatereadysnapshotcapturedevent newtbl=netdebugnetworkconnectionstatereadysnapshotcapturedevent
ugi=root ip=172.19.212.146 cmd=source:172.19.212.146 get_table : tbl=hive.nlx_dev.marrsqueryrewritecontextevent