Consolidating logs is good for performance, but can cause problems for troubleshooting in issue situations.
What I'm having trouble with is that because the logs are consolidated, it results in unsearchable logs.
For example, above, I tried to attack with an IP of 40.40.40.1, and the logs were consolidated into one log when a certain threshold was exceeded.
And after log consolidation started, I made an additional attack with the IP of 40.40.40.2, and 40.40.40.2 also remained as a consolidated log, but a single log did not exist, so I could not query it from the smart console.
So I would like to know how to not consolidate logs via DBedit or parameter change