I'm ingesting Fortigate logs using the Splunk_TA_fortinet_fortigate add-on, and I've noticed that these logs are not tagged with web, even though they seem relevant to the Web data model. Details: The logs have log_type=utm and subtype=webfilter or subtype=app-ctrl, which I believe should be mapped to the Web data model. I understand that eventtypes are defined during ingestion or at search-time, and they are used to assign tags like web. These tags are what enable CIM data model mapping. For subtype=app-ctrl, I believe only the following categories are applicable to the Web model: "Collaboration", "Instant Messaging", "Social.Media", "Streaming Media and Download", "Web.Client", "Business", "Cloud.IT", "Email", "GenAI", "General.Interest", "Video/Audio" My questions: Is the absence of the web tag due to using an older version of the TA? Has the mapping of these subtypes to the Web data model not been implemented in the current TA? If needed, is it recommended to manually define an eventtype and assign the web tag to ensure proper CIM mapping? Thanks in advance for any insights!
... View more