Is there a way to correlate FortiGate logs?

Check my post Best practice for adding additional fields to transform and try creating a transformation. It duplicate the VPN sessions to a new index with start & stop time...

1 Like