From 5b6a134a0cf2cac10422094442c4df00fc612c03 Mon Sep 17 00:00:00 2001 From: admingit Date: Thu, 24 Aug 2023 17:11:51 +0200 Subject: [PATCH] update --- .../02-M-TIC_fortigate_forwarders_inputs/local/inputs.conf | 2 +- deployment-apps/Splunk_TA_fortinet_fortigate/default/props.conf | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/deployment-apps/02-M-TIC_fortigate_forwarders_inputs/local/inputs.conf b/deployment-apps/02-M-TIC_fortigate_forwarders_inputs/local/inputs.conf index 16e0b78f..a94ccf2d 100644 --- a/deployment-apps/02-M-TIC_fortigate_forwarders_inputs/local/inputs.conf +++ b/deployment-apps/02-M-TIC_fortigate_forwarders_inputs/local/inputs.conf @@ -1,4 +1,4 @@ [monitor:///var/rsyslog/*/fortigate/*/*/*.log] disabled = false index = idx_m-tic_fortigate -sourcetype = fortigate_log \ No newline at end of file +sourcetype = fortigate \ No newline at end of file diff --git a/deployment-apps/Splunk_TA_fortinet_fortigate/default/props.conf b/deployment-apps/Splunk_TA_fortinet_fortigate/default/props.conf index 0f29a7e1..31ae4a41 100644 --- a/deployment-apps/Splunk_TA_fortinet_fortigate/default/props.conf +++ b/deployment-apps/Splunk_TA_fortinet_fortigate/default/props.conf @@ -1,4 +1,4 @@ -[fortigate_log] +[fortigate] TRANSFORMS-force_sourcetype_fortigate = force_sourcetype_fortigate SHOULD_LINEMERGE = false EVENT_BREAKER_ENABLE = true