Thanks for the quick reply! I was able to get it working with the following additional props.conf settings: [fortigate_log]
TIME_FORMAT = %s%9N
TIME_PREFIX = eventtime\=
MAX_TIMESTAMP_LOOKAHEAD = 200
[fortigate_traffic]
TIME_FORMAT = %s%9N
TIME_PREFIX = eventtime\=
MAX_TIMESTAMP_LOOKAHEAD = 200
[fortigate_utm]
TIME_FORMAT = %s%9N
TIME_PREFIX = eventtime\=
MAX_TIMESTAMP_LOOKAHEAD = 200
[fortigate_anomaly]
TIME_FORMAT = %s%9N
TIME_PREFIX = eventtime\=
MAX_TIMESTAMP_LOOKAHEAD = 200
[fortigate_event]
TIME_FORMAT = %s%9N
TIME_PREFIX = eventtime\=
MAX_TIMESTAMP_LOOKAHEAD = 200
I'm not sure if you have to restart the indexers, but I did a rolling restart.
... View more