I am unclear why you are avoiding a lookup table. You could create your table as a simple two column csv and have it auto lookup based on the event type value. And if you put this all in an "app" that you send through deployment server you have to only maintain it all in one spot. If you ever get into the TAs for the enterprise security or pci app you will find this is how they function. Make a lookup table leveraged by the sourcetype, define eventtypes, maybe assign tags based on eventtype but tags are not what you need here. The auto lookup is.
severity.csv in your lookups folder
eventtype,severity
eventtype1,5
eventtype2,4
eventtype3,4
eventtype4,2
add an eventtypes.conf
[eventtype1]
search = index=myindex source=thisone somethingthatmeansthistype
[eventtype2]
search = index=myindex source=thisone somethingelsethatmeansthistype
[eventtype3]
search = index=myindex source=thisone anothersomethingelsethatmeansthistype
edit your props.conf
adding an automatic lookup definition.
LOOKUP-severity_from_eventtype = eventseveritylookup eventtype OUTPUT severity
edit your transforms.conf
[eventseverirtylookup]
filename = severity.csv
... View more