Unparsed Logs in the Data Lake
Improvement
Logs that cannot be normalized into an OCSF event are now written to the data lake with the processing error attached, and counted in your ingestion metrics. You can search for those records, see what they contained, and see why they failed to parse.