In file default/props.conf the following aliases are defined:
[source::(MonitorWare|NTSyslog|Snare|WinEventLog|WMI:WinEventLog)...]
...
FIELDALIAS-severity_for_windows = Type as severity
FIELDALIAS-severity_id_for_windows = EventType as severity
...
Is this a bug? Should the second alias not read:
FIELDALIAS-severity_id_for_windows = EventType as severity_id
I've corrected this by overriding with a correction section in local/props.conf.
Yes, I agree. Filed as a bug.