How to influence event_type



I was hoping that I could use machine learning(event trends), to look at firewall logs. But as it sees the firewall logs as one event type, nothing useful can be gain from this.


Is there a way to influence or manipulate how the event type is found ?


Like I stated I want to use machine learning to see if "new" network patterns happens over time



