On older version of the Windows app we were using a LOOKUP to find the SID of event. This is no longer the case as of 4.1. To resolve this error, edit the default/props.conf file in your windows app to the following:
# Applying GUID, SID traslation to the "event_guid, event_sid" fields in WinEventLog sourcetype events
# [source::WinEventLog...]
# LOOKUP-GUID = guid_lookup guid_lookup AS guid_to_trans OUTPUT dcName AS guid_dcname
# LOOKUP-SID = sid_lookup sid_lookup AS sid_to_trans OUTPUT cn AS sid_cn dcName as sid_dcname
# Applying GUID, SID traslation to the "guid_raw, sid_raw" fields in WMI WinEventLog sourcetype events.
# By looking up the values of those two fields, two new fields are generated, guid_name, sid_name
# [source::WMI:WinEventLog...]
# LOOKUP-GUID = guid_lookup guid_lookup AS guid_to_trans OUTPUT dcName AS guid_dcname
# LOOKUP-SID = sid_lookup sid_lookup AS sid_to_trans OUTPUT cn AS sid_cn dcName as sid_dcname
... View more