Troubleshooting Incorrect Severity in EventLog Analyzer Custom Report
Overview
This document provides guidance to identify and resolve issues where the severity levels in EventLog Analyzer custom reports appear incorrect, ensuring accurate and reliable reporting.
Possible Causes
Misconfigured severity mapping in EventLog Analyzer.
Log source sending incorrect severity information.
Custom rules or filters overriding default severity levels.
Outdated EventLog Analyzer version or missing patches.
If the log type is not set in a custom report, EventLog Analyzer assumes it is a Syslog log and assigns severity based on these levels, which can cause mismatches.
Prerequisites
Access to edit and update the respective custom report.
Administrative access to EventLog Analyzer, if required for configuration changes.
Resolution
In your EventLog Analyzer, go to Reports → Manage Reports → Edit the respective custom report.


Click on the "+" icon to add a field in the criteria and choose the field LogType.
If the log source is a Windows device, select the LogType as "Windows Event Log" or any specific log type from the drop-down.
Ensure the operator selected is AND.
Click on Update to save the changes.

Tips
Always specify the correct LogType while creating or editing custom reports to avoid mismatched severity levels.
Cross-check the device type (Windows, Syslog, etc.) before finalizing report criteria.
Keep EventLog Analyzer updated with the latest patches to avoid known issues.
EventLog Analyzer build information.
Screenshots or export of affected reports.
Screenshot of the custom report criteria
Screenshot of Log Collection filter page
Related articles and topics
New to ADSelfService Plus?
Related Articles
Unable to start EventLog Analyzer
Issue description This issue occurs when the EventLog Analyzer service fails to start, or when users are unable to access the web client through the browser (typically on ports 8400 or 8445). Users may experience one or more of the following ...
Troubleshooting: The report export does not have the message field in EventLog Analyzer
Issue description In EventLog Analyzer, users may encounter that the Message field is not available while exporting specific reports. This typically occurs when the selected report or its associated data source lacks the inclusion of the Message ...
Introduction to EventLog Analyzer
What is log management? An enterprise network consists of different entities—perimeter devices, workstations, servers, applications, and more. Each entity records every activity that unfolds within it in the form of logs. These logs hold information ...
Troubleshooting guide: EventLog Analyzer UI is unresponsive
Overview This document outlines the common causes and recommended steps to resolve the issue when the EventLog Analyzer UI becomes unresponsive. Possible causes Insufficient system resources High CPU or memory usage on the server. Low disk space in ...
How time conversion works in EventLog Analyzer
Objective This article explains how time conversion is handled in EventLog Analyzer while accessing log data when the EventLog Analyzer server and endpoint devices operate in different time zones. It also provides guidance on how to identify and ...