Unparsed Logs in the Data Lake

Improvement

Logs that cannot be normalized into an OCSF event are now written to the data lake with the processing error attached, and counted in your ingestion metrics. You can search for those records, see what they contained, and see why they failed to parse.

Learn More