
I have seen Firepower logs work fine in Logpoint, but it was last a couple of years ago. We would probably need to see what actually happens, e.g. a screenshot or copy/paste of your raw logs. When you say “better” normalisation, what do you see vs. what did you expect? Enrichment is independent of the data source, so again it would be a question of what are you getting vs. what did you expect?
Because it might be sensitive data, this might also best be done through a Support ticket.
2 comments