Hi everyone, I'm facing issues with the Fortinet module in Filebeat. It stores the whole log in the message field instead of seperate fields.
This is an example of my log (I removed some info such as IPs): https://pastebin.com/5Te8SiHX
How can I get the message field split up? When I set up the module, I followed all the steps mentioned in the documentation. The module is listed as enabled and is sending logs to logstash. I also disabled and enabled the module. It didn't help.
This is how my fortinet.yml looks like: https://pastebin.com/WPkmMQS6
I know I could add a filter to logstash but that would make the module redundant.
Has anyone faced a similar issue before? Any help is appreciated!