QuestionQ38
Parsing and NormalizationWhile reviewing logs, you discover that incoming firewall-log content appears as a single large block of text in the @rawstring field. The other anticipated structured fields are empty.
What is causing this issue?
- A The parser was incorrect
- B The ingestion token is invalid
- C The sink was overloaded
- D The timestamp format is incorrect
Community Discussion