I am trying to find exactly how the Windows Event Forwarder maps event logs to syslog severity levels. Is there any documentation on this? I have some informational messages in the Windows event log that are categorized as emergency messages on my NPM syslog server.
John