Up until now, everything has been going along just fine, but for whatever reason, I cannot get certain fields to show up in the event. For example:
values(duser) as "user" in my search returns a value in the stats table of "user" as "email@example.com", but this does not show up in the notable event using the same search, and calling the variable $user$ in the notification description returns "Unknown".
I have checked in my customized copy of log_review.conf, and the field "user" is correctly defined. Other CIM and custom defined fields work for the same event, and even adding another field/label pair in log_review.conf doesn't seem to work for this particular field. get_event_id and map_notable_fields macros are both used in the search.