Hi everyone,
I am currently testing ElastiFlow v7.26.2 in my environment and have encountered an issue with Cisco ASA NSEL (NetFlow Security Event Logging) event parsing.
Specifically, during my testing, I noticed that the standard firewall_event field is completely missing, while the fw_ext_event field is populated correctly. According to the Cisco NSEL specifications, both standard and extended event IDs should map to their respective human-readable meanings, but currently, only the extended ones are appearing.