Troubleshooting Incorrect Severity in EventLog Analyzer Custom Report

Troubleshooting Incorrect Severity in EventLog Analyzer Custom Report

Overview

This document provides guidance to identify and resolve issues where the severity levels in EventLog Analyzer custom reports appear incorrect, ensuring accurate and reliable reporting.

Possible Causes

  • Misconfigured severity mapping in EventLog Analyzer.
  • Log source sending incorrect severity information.
  • Custom rules or filters overriding default severity levels.
  • Outdated EventLog Analyzer version or missing patches.
  • Windows groups events into levels such as,
    • Information
    • Warning
    • Error
    • Critical
    • Emergency
  • Syslog groups events into severity levels as (0–7):
    • 0 – Emergency
    • 1 – Alert
    • 2 – Critical
    • 3 – Error
    • 4 – Warning
    • 5 – Notice
    • 6 – Informational
    • 7 – Debug
If the log type is not set in a custom report, EventLog Analyzer assumes it is a Syslog log and assigns severity based on these levels, which can cause mismatches.
Prerequisites
  • Access to edit and update the respective custom report.
  • Administrative access to EventLog Analyzer, if required for configuration changes.

Resolution

  1. In your EventLog Analyzer, go to Reports → Manage Reports → Edit the respective custom report.




  2. Click on the "+" icon to add a field in the criteria and choose the field LogType.
  3. If the log source is a Windows device, select the LogType as "Windows Event Log" or any specific log type from the drop-down.
  4. Ensure the operator selected is AND.
  5. Click on Update to save the changes.

Tips

  • Always specify the correct LogType while creating or editing custom reports to avoid mismatched severity levels.
  • Cross-check the device type (Windows, Syslog, etc.) before finalizing report criteria.
  • Keep EventLog Analyzer updated with the latest patches to avoid known issues.

How to contact support

If the issue persists, contact ManageEngine support with the following details:
  • EventLog Analyzer build information.
  • Screenshots or export of affected reports.
  • Screenshot of the custom report criteria
  • Screenshot of Log Collection filter page

Related articles and topics

 

                  New to ADSelfService Plus?

                    • Related Articles

                    • Unable to start EventLog Analyzer

                      Issue description This issue occurs when the EventLog Analyzer service fails to start, or when users are unable to access the web client through the browser (typically on ports 8400 or 8445). Users may experience one or more of the following ...
                    • How and when to choose Summary View for creating custom report in EventLog Analyzer

                      Objective This article offers you the steps to create custom report as Summary View in EventLog Analyzer. It will guide you through the process of generating custom report as Summary View and offer a brief idea on when to use this option for your ...
                    • How and when to choose Pivot View for creating custom report in EventLog Analyzer

                      Objective This article offers you the steps to create custom report as Pivot View in EventLog Analyzer. It will guide you through the process of generating custom report as Pivot View and offer a brief idea on when to use this option for your ...
                    • How to create a custom report view in EventLog Analyzer

                      Objective EventLog Analyzer allows you to create multiple views of the same report. This enables you to view the report based on different parameters such as time, domain, source, etc. The different views will be generated from the same set of log ...
                    • How to customize a predefined report in EventLog Analyzer

                      Objective EventLog Analyzer offers option to build criteria or refine the predefined reports by adding filters and to save them as custom report. Adding filter offers you an option to filter out specific data based on the criteria that you build ...