Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

severity_id bug?

$
0
0
In file default/props.conf the following aliases are defined: [source::(MonitorWare|NTSyslog|Snare|WinEventLog|WMI:WinEventLog)...] ... FIELDALIAS-severity_for_windows = Type as severity FIELDALIAS-severity_id_for_windows = EventType as severity ... Is this a bug? should the second alias not read: FIELDALIAS-severity_id_for_windows = EventType as severity_id I've corrected this by overriding with a correction section in local/props.conf.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>