Accesses to AccessList mapping

View thread

opoplawski

I'm sending im_msvistalog messages to splunk via to_json().  I'm ending up with a field AccessList like:

AccessList: %%4423

which I assume is some kind of mapping of:

Access Request Information: Accesses: ReadAttributes

from the “Message” component.  Is that right?  If so, it's fairly obscure.  Is there some way to preserve “Accesses” as is?  What is “AccessList” trying to tell me?  Is there somewhere I can go to decode it?