You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Mar 13, 2018. It is now read-only.
It's a feature of windows eventlog API (or java library itself) I suppose. Anyway I use this Drools rule to fix the problem.
import org.graylog2.plugin.Message
rule "Rewrite Windows Eventlog Event Id"
when
m : Message(hasField("event_id"))
then
m.addField("event_id", Long.parseLong(String.valueOf(m.getField("event_id"))) & 0xFFFF);
end
Example: In the EventLog the ID ist 7036.
In the corresponding graylog entry I can only find
event_id 1073748860
event_record_number 29773.
hmmm...
The text was updated successfully, but these errors were encountered: