All Apps and Add-ons

Splunk Add-on for Microsoft Windows: Is this a bug with the field alias for severity_id in props.conf?

otaci
Explorer

In file default/props.conf the following aliases are defined:

[source::(MonitorWare|NTSyslog|Snare|WinEventLog|WMI:WinEventLog)...]
...
FIELDALIAS-severity_for_windows = Type as severity
FIELDALIAS-severity_id_for_windows = EventType as severity
...

Is this a bug? Should the second alias not read:

FIELDALIAS-severity_id_for_windows = EventType as severity_id

I've corrected this by overriding with a correction section in local/props.conf.

1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Yes, I agree. Filed as a bug.

View solution in original post

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Yes, I agree. Filed as a bug.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...