App_Firewall_info section in Global Log Receiver messages

App Firewall security event include a section called app_firewall_info. This section is available via the Security Event (json). But in a Global Log Receiver type Splunk (not checked with others), it is not included.


"app_firewall_info": { "name": "my-policy", "action": "block", "description": "Disallowed response code (404)" },



  • Matthieu Dierick
  • Apr 14 2023
  • Will not implement
  • Attach files
  • Admin
    Nicolas Cartron commented
    May 16, 2023 11:41

    now working properly