Splunk Search

Does the Windows TA nullify the Windows field called Error Code?

danielbb
Motivator

It's similar to Windows TA not Parsing "Error_Code" from 4776 Logs

My take on that is -

The TA does the following - if a field by the name Status (Windows field) exists, its value is being copied to a new field called Error_Code (Splunk field). If Status has no value, Error_Code would have a dash (-). So, it's a field alias.

Now, if Error_Code existed already as a Windows field, then Error_Code would be overridden by the value of the Status field or a dash.

So, we end up losing lots of data.

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...