FortiSIEM log normalization
As we're expanding the use of our FortiSIEM, we've realized that not all logs are normalized properly, completely or in some case not at all. As we're fairly new to FortiSIEM, we're trying to figure out how to approach this - if we need to create our own normalization packages, if we can request them from Fortinet, if there are vendor-specific packages that can be requested or downloaded somewhere?
If we need to create our own, are there tools or do we copy an existing package and start working out what's what in the log we want to normalize?
