Windows event log monitoring monitors event logs generated in the system viewer of all Windows devices in your network. Alerts are generated depending on the conditions specified in the monitor.

The Windows event log monitoring involves the following functions:

  • Defining the preprocessing policy in the cloud.
  • Receiving, preprocessing, and normalizing the logs in the agent.

Configure Windows event log monitoring using one of the following methods.

  • Creating a template
  • Assigning the template from devices

Configure an event log monitor when creating a template

  1. Select a client from the All Clients list.

  2. Go to Setup > Monitoring > Templates.

  3. Click + Add.

  4. Enter the following information:

    PropertyDescription
    Select Template Scope(required) Template scope:
    • Partner Template
    • Client-specific Template
    Client(required) If Client-specific Template is selected, drop-down client list.
    Collector Type(required) For Windows event logs, select Agent.
    Applicable For(required) Select G1 Monitors or G2 Monitors.
    Template Name(required) Template name.
    Description(required) Template description.
    GenerationGeneration template belongs to. Prepopulated depending on the Applicable For selection.
    VersionTemplate version. Fixed value = 1.
    TagsUser-defined tags for easy reference.
    PrerequisitesUser-defined prerequisites of what to consider when using this template.
    StatusTemplate status:
    • (default) Active
    • EOL: end-of-life
    • Inactive
    NotesTemplate notes.
    Template Family NameUser-defined template family name.
    Deployment TypeDeployment type:
    • Custom
    • Optional
    • (default) Standard
  5. Expand the Event Log Monitor section by clicking + Add.

  6. Enter the following properties:

    Monitor Template-1
    Monitor Template-2
    PropertyDescription
    FrequencyLog monitoring frequency. Recommended: 15 minutes.
    AlertSelect to initiate monitoring.
    PriorityPriority level:
    • P0
    • P1
    • P2
    • P3
    Log TypeFor each category you want to associate with the event logs, select the severity level(s):
    • All: Select all severity levels.
    • Error
    • Critical
    • Information
    • Success
    • Warning
    ArticlesKnowledge base articles to attach to the template. Choose Select or Modify and select from the list of articles.
    SourceSource names to monitor the events. You can enter multiple comma-separated sources.
    Event IdsRequired event IDs. You can enter multiple comma-separated event IDs.
    Message StringEvent description or regex to to match against monitored events. You can enter multiple message strings separated by $$. The message string field supports both normal and regex strings. the following characters must be preceded by the \ escape character: [,],{,},(,),$,+,*,/,\
    Alert ComponentThe Alerts Component field requires users to enter the component name. The purpose of adding the Alert Component is that if the eventlog source names and eventid are the same but the message search string is different, the agent will create a separate eventlog alert based on the given component name.
    The Alerts Component field is optional, and the alert component support is only available for the included drop-down filter.
    Included/ExcludedFrom the drop-down, select:
    • Included: Monitor only the specified source name and event IDs or both from the specified input selected categories.
    • Excluded: Skip specified source name and event IDs, or both, monitoring from the input selected categories.
  7. Click Save to apply the configuration parameters.
    After configuring an event log monitor, the agent begins collecting data according to the specified event log parameters and sends them to the cloud.

Configure an event log monitor when assigning a resource template

When event fields match the configured selection criteria those events sent as a critical alert.

  1. Select a client from the All Clients list.

  2. Go to Infrastructure > Resources and select the resource you want from the list of resources. You can use the search option to find a resource.

  3. Click the resource name to view resource details.

  4. Now, go to Monitors > Monitors > +AssignMonitors.

  5. In Add Monitor page, select Agent from Collector Type and Category as Event Log Monitor and then enter the following details:

    PropertyDescription
    FrequencyLog monitoring frequency. Recommended: 15 minutes.
    AlertSelect to initiate monitoring.
    PriorityPriority level:
    • P0
    • P1
    • P2
    • P3
    Log TypeFor each category you want to associate with the event logs, select the severity level(s):
    • All: Select all severity levels.
    • Error
    • Critical
    • Information
    • Success
    • Warning
    ArticlesKnowledge base articles to attach to the template. Choose Select or Modify and select from the list of articles.
    SourceSource names to monitor the events. You can enter multiple comma-separated sources.
    Event IdsRequired event IDs. You can enter multiple comma-separated event IDs.
    Message StringEvent description or regex to to match against monitored events. You can enter multiple message strings separated by $$. The message string field supports both normal and regex strings. the following characters must be preceded by the \ escape character: [,],{,},(,),$,+,*,/,\
    Alert ComponentThe Alerts Component field requires users to enter the component name. The purpose of adding the Alert Component is that if the eventlog source names and eventid are the same but the message search string is different, the agent will create a separate eventlog alert based on the given component name.
    The Alerts Component field is optional, and the alert component support is only available for the included drop-down filter.
    Included/ExcludedFrom the drop-down, select:
    • Included: Monitor only the specified source name and event IDs or both from the specified input selected categories.
    • Excluded: Skip specified source name and event IDs, or both, monitoring from the input selected categories.
  6. Click Save to apply the configuration parameters.