Hello,
I collect the fortigate events.
I configured the geoip plugin in logstash.
The visualization of sources before configuring the plugin is different after configuring the plugin.
Please find the difference below:
Can you explain to me why the list of ip before configuring the plugin is different from the list linked to Geoip?
Can you explain to me why we have UnitedStates which produces the most events on the fortigate logs and Amsterdam is in fourth position. And on the Geoip_timezone, is Amsterdam which produces the most events and UnitedStates is in fourth position?
Regards,