rule “convert level to severity”
when
has_field(“level”)
then
let result = to_string($message.level);
let levelMap = key_value(“0=EMER 1=ALERT 2=CRIT 3=ERROR 4=WARNING 5=NOTICE 6=INFO 7=DEBUG”);
set_field(“level”, to_long(levelMap[to_string(result)]));
end
But this no work…
help please how i can do custom convert log level numbers to severity…
rule "convert level to severity"
when
has_field("level")
then
let levelMap = key_value("0=EMERGENCY 1=ALERT 2=CRITICAL 3=ERROR 4=WARNING 5=NOTICE 6=INFO 7=DEBUG");
set_field("level", to_string(levelMap[to_string($message.level)]));
end