Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

log.syslog.severity.name incorrect #1948

Open
abraxxa opened this issue May 31, 2022 · 2 comments · May be fixed by #2290
Open

log.syslog.severity.name incorrect #1948

abraxxa opened this issue May 31, 2022 · 2 comments · May be fixed by #2290
Labels
bug Something isn't working

Comments

@abraxxa
Copy link

abraxxa commented May 31, 2022

Description of the issue:
The description of the field log.syslog.severity.name says: The Syslog numeric severity of the log event, if available.

The correct wording would be something like: The Syslog textual severity of the log event, if available.

Their exact strings should also be included to standardize them for easier filtering. Wikipedia lists keywords but I couldn't find them in RFC5424. Therefore I'm proposing to use the severity names as listed in RFC5424. If possible the field mapping should ignore the case, allowing to store them unmodified but still finding all possible case variants.

@abraxxa abraxxa added the bug Something isn't working label May 31, 2022
@ebeahan
Copy link
Member

ebeahan commented May 31, 2022

@abraxxa, thanks for this issue. I agree the log.syslog.severity.name field's description should describe capturing the text/keyword/label value and not the numeric value.

Their exact strings should also be included to standardize them for easier filtering.

Past conversation in #129 discussed this type of standardization in-depth in a new event.* field, but the conversation later stalled. If there's renewed interest, perhaps the conversation could continue there. However, I believe capturing the raw, unmodified value extracted from the source event in log.syslog.severity.name remains useful.

@abraxxa
Copy link
Author

abraxxa commented Jun 1, 2022

Thanks for the pointer to #129!

My intent was only to fix the docs and standardize the values in the log.syslog.severity.name field.
Normalizing them is a larger undertaking 😉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants