I don't think changing props.conf will help.
If we think this through, you were using v4.8.4 for which sourcetype is WinEventLog://<application>|<System>|<Security> then, the latest version for which all sources (app, sys, sec) are assigned one sourcetype WinEventLog then rolled back to v4.8.4. So, you're having a mixture of old and new sourcetypes for the events.
My suggestion is continue searching on source="WinEventLog:Security" in searches or reports or locate and modify savedseaches.conf (all your searches and reports and alerts are saved in this file) to include * in sourcetype name inside searches.
Note: You might not find savedsearches.conf for some add-ons.
... View more