Hi,
We are seeing log parsing issue with Juniper SRX logs for the following logs
RT_FLOW_SESSION_CREATE
RT_FLOW_SESSION_CLOSE.
It doesn't parsing at all. As far as i could see from the release notes that the Add-on has a known issues with Junper SRX Logs Parsing for RT_FLOW_SESSION_CLOSE_LS. However not with the ones which i mentioned above (RT_FLOW_SESSION_CREATE or RT_FLOW_SESSION_CLOSE).
Can you please help. Is this related. ?
Date filed Issue number Description
2022-12-29 ADDON-59372 Junper SRX Logs Parsing for RT_FLOW_SESSION_CLOSE_LS
As far as I remember the Add-on we got from splunkbase (but I admit, it was some 4 years ago or something like that) wouldn't parse some fields properly. We ended up fixing the transforms by hand.