FIELDS @message
| PARSE @message "* [*] *" as loggingTime, loggingType, loggingMessage
| FILTER loggingType IN ["ERROR", "INFO"]
| DISPLAY loggingMessage, loggingType = "ERROR" as isError
messageにたいしてawk的なやつはなくって、正規表現でいい感じに区切ることしかできなっぽい