My problem is the field 'Type' is not populated for the logs that i'm sending into ESM (thub integrated esm if matters, th-cef->avro->avro-enriched->avro-esmfiltered). There are a lot of builtin rules which uses this information. For the time being i have created a pre-persistence rule, which adds the type "Base" to logs that have it without value. Wondering where the value gets added to the events, and where it gets lost.
Thank you in advance.