Hi,
After upgrade of the app to 4.3.1 I notice that I don't have in trafic log the info about origin_sic_name=
For the sourcetype=opsec (for the other sourcetype, I have the info in the log)
The field I used to ID wich firewall log it belonged to in the setup of a cluster.
where is this log tag gone ? how to reactivate it ?
Marc
the same for me. Since last update, the origin_sic_name doesn't appear anymore.
Probable there was a change in eventgen.conf since last update (?).