I noticed that some logs I collect have a field "severity" (ips logs). This is in conflict with the field "severity" which is related to my syslog input : severity of syslog is long and severity of ips logs is string (i.e "high"). This way, my ips log can't be indexed
I didn't found a way to disable all fields related to sysog input : severity, severity label, facility and facility label. Do you know a way to achieve this ? (or a workaround)
Thank you !