I'm getting probably an issue with the extraction of my Fortinet data. I have installed the following apps:
Does anyone know the different of the field action and ftnt_action? because I'm getting different results there.
In field action do I have for example "blocked" but in ftnt_action do I have "detected" and also "dropped". This is a bit confusing while I'm trying to get only blocked attacks.
Could someone please help me?