Skip to content

[Filebeat][Fortinet Module] Can we include hardware id in observer.serial_number in fortimail fileset, just in like firewall fileset? #25254

@kunisen

Description

@kunisen

Describe the enhancement:
Describe a specific use case for the enhancement or feature:

We use firewall fileset of Filebeat Fortinet module.
We found that, unlike the firewall fileset in the fortinet module, the device ID was not set to observer.serial_number.
Therefore we need to set it manually like this in pipeline.yml.

​ - rename:
field: rsa.misc.hardware_id
target_field: observer.serial_number
ignore_missing: true

Could we improve this in the future version please?

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions