Hi folks, I'm working on testing log ingestion from the Firewall to splunk.

Rules are firing correctly and now logging but the issue is i see no details around the actual block/drop.

Here is an example of the output. Do i need to dial up the log info detail?

uvm[0]: {"timeStamp":"2021-04-29 16:11:20.767","flagged":true,"blocked":true,"sessionId":105880637112421,"ruleId":100001,"class":"class com.untangle.app.firewall.FirewallEvent"}

Any guidance would greatly be appreciated!