Hi,
Thank you for following up. We are working on releasing an update for the Splunk Add-on for Bro which includes fixes to the ones you have highlighted and others.
ADDON-2206 will not be fixed because a single event cannot have both conn_state & status fields to do the lookup. Events of sourcetype "bro_conn" have "conn_state" field, and sourcetype "bro_http" & "bro_ssh" events have "status" field. As a result, the "action" field that is outputted by both lookups will not conflict.
Let us know if you have any questions.
... View more