theopolis
06/15/2020, 11:38 PMMike Myers
06/16/2020, 5:42 PMalessandrogario
06/18/2020, 1:09 PMdata
column has been slightly changed; instead of adding the fields directly inside a single object (example: { "key": "value"}
), we now have a root "Data" object (example: { "Data": { "key": "value" } }
). This allows us to extend this with additional data from the Windows Event Log XML without breaking compatibilityseph
06/18/2020, 2:21 PMuint64_t
alessandrogario
06/18/2020, 2:37 PMseph
06/18/2020, 2:37 PM{data: {...}}
means you can add {metadata: {}}
or somethingalessandrogario
06/18/2020, 2:37 PMseph
06/18/2020, 2:37 PMalessandrogario
06/18/2020, 2:38 PMseph
06/18/2020, 2:38 PMlauncher
tables, I’ve struggled a bit with this. For runtim e variable/unknown data fields, there’s no good translation to columns.
I don’t like dealing with json
data, it’s hard to merge/sort/join on it. I usually end up with an EAV model.alessandrogario
06/18/2020, 2:45 PMpacketzero
06/18/2020, 3:49 PMalessandrogario
06/18/2020, 4:43 PMpacketzero
06/18/2020, 4:44 PMalessandrogario
06/18/2020, 4:44 PMseph
06/18/2020, 5:15 PM