hi @dot-mike, I think we would broaden it out to all Fortinet data instead of Fortigate. I was looking at our integration data streams and they all seem to set observer.vendor to "Fortinet", so maybe that is the filter we could use to get the count.
If you have some data locally maybe you could confirm this filter brings back the expected count?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.