Log files are uploaded to upload.threatpulse.com but no reporting data is displayed even waiting 24 hours later.
it is important to run the LogChecker on the logs that will be uploaded to upload.threatpulse.com. The log fields that MUST be included are:
date
time
cs-host
sc-status
cs-uri-scheme
If one of the above fields are not included the logs will fail to be processed and and no new reporting data will be added to the current reporting data seen in portal.
Extra fields that will help populate canned reports in portal but are not required are:
c-ip
cs-username
x-exception-id
cs-categories
cs(Referer)
s-action
rs(Content-Type)
cs-uri-path
cs-uri-query
x-virus-id