I tried to add the xauthuser field to the data model ftnt_fos and after that I get no results any more. Did I break it?
The xauthuser field carries the username that connected to the firewall using an ipsec tunnel, it's a critical field for the vpn dashboard.
In the Splunk web ui I went to Settings/Datamodels, then opened the "Fortinet FOS Log" datamodel:
Now when I go to any Fortigate pre-built dashboard I get "No results".
what file are you changing? the datamodel should be defined in SplunkAppForFortinet/default/data/models/ftnt_fos.json
what are your changes? please paste it here.
which dashboard query on vpn are you adding/customizing?