logstash用grok进行日志过滤截取

logstash接收到的日志内容"message" => "{"@timestamp":"2022-11-03T16:23:21.084+08:00","@version":"1","message":"==> Preparing: SELECT COUNT(handle_code) \"triggerDayCount\", SUM(CASE WHEN (trigger_code in (0, 200) and handle_code = 0) then 1 else 0 end) as \"triggerDayCountRunning\", SUM(CASE WHEN handle_code = 200 then 1 else 0 end) as \"triggerDayCountSuc\" FROM xxl_job_log WHERE trigger_time BETWEEN ? and ?","logger_name":"com.xxl.job.admin.dao.XxlJobLogDao.findLogReport","thread_name":"xxl-job, admin JobLogReportHelper","level":"DEBUG","level_value":10000,"tags":["MYBATIS"],"appname":"xxlAdmin"}"
这个用grok怎么按字段截取,
比如"level_value":10000, 截取成leve_value:10000这种