diff --git a/deployment-apps/02-M-TIC_fortigate_forwarders_inputs/local/inputs.conf b/deployment-apps/02-M-TIC_fortigate_forwarders_inputs/local/inputs.conf index 16e0b78f..a94ccf2d 100644 --- a/deployment-apps/02-M-TIC_fortigate_forwarders_inputs/local/inputs.conf +++ b/deployment-apps/02-M-TIC_fortigate_forwarders_inputs/local/inputs.conf @@ -1,4 +1,4 @@ [monitor:///var/rsyslog/*/fortigate/*/*/*.log] disabled = false index = idx_m-tic_fortigate -sourcetype = fortigate_log \ No newline at end of file +sourcetype = fortigate \ No newline at end of file diff --git a/deployment-apps/Splunk_TA_fortinet_fortigate/default/props.conf b/deployment-apps/Splunk_TA_fortinet_fortigate/default/props.conf index 0f29a7e1..31ae4a41 100644 --- a/deployment-apps/Splunk_TA_fortinet_fortigate/default/props.conf +++ b/deployment-apps/Splunk_TA_fortinet_fortigate/default/props.conf @@ -1,4 +1,4 @@ -[fortigate_log] +[fortigate] TRANSFORMS-force_sourcetype_fortigate = force_sourcetype_fortigate SHOULD_LINEMERGE = false EVENT_BREAKER_ENABLE = true