I've just installed v1.5.0 of the app from SplunkBase and I'm seeing errors in index=_internal saying "Invalid eval expression for 'EVAL-file_extension` in stanza [source::WinEventLog:Microsoft-Windows-Sysmon/Operational]: Missing arguments."
Looking at props.conf - I can see the line:
EVAL-file_extension =
ie there is nothing to the right of the equal sign.
I've just installed v1.5.0 of the app from SplunkBase and I'm seeing errors in index=_internal saying "Invalid eval expression for 'EVAL-file_extension` in stanza [source::WinEventLog:Microsoft-Windows-Sysmon/Operational]: Missing arguments."
Looking at props.conf - I can see the line: EVAL-file_extension = ie there is nothing to the right of the equal sign.