Oh, this filter GROK is very interesting, I did not know it! From what I read on the site, it manages to fill some holes that KV can not handle, and that's probably going to work! Unfortunately, I can't test this solution now, but tomorrow I will return with news!
in fact is a bad name , this solution comes from the fortigate itself and has the function of identifying an event based on the type -> subtype -> level, but I will think of an alternative name haha
Um, now you've left me in doubt @VamPikmin! I just start to work with fortigate and i do not know it very well, so I may have confused, but I will try to confirm this information!
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.