Hi all,
I have data coming in, parsing and indexing correctly to a windows index. This data comes in with either one of two sourcetypes: "WinEventLog" and "wineventlog". The sources appear to be the same, so I am having difficulty understanding what corresponds to each sourcetype. Any help is appreciated. Thank you.
@TheBravoSierra - Are you having Sysmon data? That may have "wineventlog" (lower case) sourcetype value.
Since sourcetype is case-sensitive (regarding props.conf and event processing) so strictly technically these are two distinct sourcetypes. It seems though that for some reason (probably backwards compatibility) they share definitions in TA-windows.
Generally, you should be using the new name - WinEventLog.