For example, i see Regex to change source type from pan:log to pan:threat as,
REGEX = ^[^,]+,[^,]+,[^,]+,THREAT,
However, the exact piece this regex is seeking for in raw data i am receiving is
,2020/02/21 22:09:08,,TRAFFIC,
With two comma in roll the add on is not doing any sourcetype change then...
I am receiving this logs from Cortex, not sure whether it could do something with it?
Thanks a lot
... View more