elastic / elastic/integrations

[fortinet_fortigate]: fortinet.firewall.packetloss should be a Numeric Type

Open
#12,152 3 comments 0 reactions 0 assignees View on GitHub
breaking change Integration:fortinet_fortigate Stalled Team:Security-Deployment and Devices
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
2d 17h
Merged PRs (30d)
225

Description

### Integration Name

Fortinet FortiGate Firewall Logs [fortinet_fortigate]

### Dataset Name

fortinet_fortigate.log

### Integration Version

1.27.0

### Agent Version

8.16.1

### Agent Output Type

elasticsearch

### Elasticsearch Version

8.16.0

### OS Version and Architecture

Ubuntu 24.04.1 LTS

### Software/API Version

FortiOS 7.0.16

### Error Message

_No response_

### Event Original

_No response_

### What did you do?

Default Integration and receiving SDWAN logs from firewall

### What did you see?

The field in the index for fortinet.firewall.packetloss is set to keyword.

### What did you expect to see?

Changing fortinet.firewall.packetloss to a numeric type would allow for alerting to be written based on the packet loss being above or below a specific threshold. The value comes in as number with three values after the decimal i.e. 90.000

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.