I store log automatically every day into opensearch with patern fortigate-logs%{+YYYY-MM-dd}
Now each day an index will be created for each day.
When I want to create correlation rule
, I should choose an index, How can I tell opensearch select pattern instead of an index?
Have you tried an index alias instead?
Here is more info at Index aliases - OpenSearch Documentation
Looking at Docs, you can specify index patterns as well: Creating correlation rules - OpenSearch Documentation
“Select index dropdown list, specify an index or index pattern…”
something like:
fortigate-logs*
Best,
mj
This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.