Quote from: keeka on March 28, 2026, 07:56:00 AMIn the meantime ;-) are you able to modify the grok expression to cater for both formats?
Trying to figure out how to do that very thing...
Quote from: franco on March 28, 2026, 07:59:14 AMIf you add a ticket on GitHub that's something to consider for improvement. I agree that it shouldn't differ but we need to isolate the code bits responsible first to make a meaningful plan forward.
https://github.com/opnsense/core/issues/10059
"