Hi , does anyone have any experience with Parsing Version 6 schema of Umbrella logs
the release notes from the addon https://splunkbase.splunk.com/app/3926/ talks only of version5
1.0.5: Adds support for logging format version 5 + Firewall Logs
the change in Umbrella seems for my environment to be only from Version4 -> version6 and
"Schema upgrades are one way; you will not be able to revert this upgrade."
Its scary you cant revert
Anyone moved to version6 and did they make changes in the local/{props,transforms} ?