Hi everyone, I have configured Fortigate to send logs to Elasticsearch. However, when there's a long live session, Fortigate creates a duplicate session ID every 2 minutes and consistently adds data size to the previous one. This results in inaccurate data being displayed in Elasticsearch.
If anyone can help me to filtre network.bytes by the last duplicate session id
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.