Configuring Windows Event Log in TrueSight


This topic provides information about configuring and monitoring Windows event logs by using the TrueSight and the Central Monitoring Administration console.

On the Add Monitoring Configuration dialog, set the following preferences:

Monitoring Solution

Monitor Proile

Monitor Type

Microsoft Windows Servers

Event Log

Windows Event Log

Windows event logs basic configuration video

Click to view a short video (4:48) of how to configure Windows event logs for monitoring. 

icon_play.png https://youtu.be/j1E380MhBYQ

Windows event logs advanced configuration video

Click to view a short video (7:09) of how to configure Windows event logs for monitoring. 

icon_play.png https://youtu.be/MOPOa2zd1IA

Configuration details

On the Add Monitor Types dialog, with the Monitoring Profile set to Event Log or Operating System, and the Monitor Type set to Windows Event Log, provide the following details:

Event Log Configuration Event Log: Select this check box to enable Event Log monitoring. By default, all Windows event logs are monitored if they are registered in the Windows registry at the following location: 

HKLM\SYSTEM\CurrentControlSet\Services\Eventlog 

List of Event Logs: Click Add button.png button to configure the event logs. 

Log Name

Specify the event log name for which you want to create a filter.

For example, you can enter Application or System or Security or operational event logs like, Microsoft-Windows-WinRM/Operational as the log name.

Forward Windows Events To Event Manager

Select this option to forward either all, or filtered or no events to the event manager.

  • Do not forward Windows Events to Event Manager
  • Forward all Windows Events to Event Manager
  • Forward filtered Windows Events to Event Manager

Use File Bookmark

This field indicates whether each event log should use a checkpoint value to guarantee that no events are missed in the event that the PATROL Agent or the KM is not loaded for a period of time.

List of Filters:  Click Add button.png button to filter the event logs. 

Name

Enter a unique name that represents the event filter, and follows these rules:

  • The filter name cannot exceed 127 characters.
  • The filter name cannot use the following format: user@domain.com. If this format is used for the filter name, the filter fails to filter events.

Description

Enter a short description of the filter you are creating. This is additional information regarding the filter and you can change the description at any time.

Report/Notify

Select one of the following options, as appropriate:

Source Details

Click Add button.png button to configure the source name. 

Name

Specify the event log source name or a regular expression.

OK

Click to save the configuration.

Cancel

Click to close the dialog.

 

Use name as a regular expression

Select this check box if you specified a regular expression in the Name field.

Disable case sensitivity

Select this check box to disable case sensitivity for the source filtering.

You can specify whether to make filter comparisons in a case-independent manner for the source, user, category, and string options of a Windows event filter. To disable case-independent comparisons for any of the options, ensure that the corresponding Disable Case Sensitivity check box while configuring windows event monitoring is cleared.

The /PSX_P4WinSrvs/PWK_PKMforMSWinOS_config/EventLogMonitoring/eventlog/EventFilters/filter/FilterDisableCase configuration variable stores information about case-sensitivity of the event filter options.

This variable has five bit values, depending upon case sensitivity, one bit corresponding to each of Source, User, Category, String, and Computer name, respectively. If any bit value is 1, a case-independent filter comparison is made for the corresponding field.

You can set this variable to either of the following values:

  • 00000 = none checked (default)
  • 11111 = all 5 categories checked
  • A combination of 0s and 1s, depending on which of the 5 categories were checked

To disable case-sensitivity in the event filters, set the value of the FilterDisableCase configuration variable to 00000.

Include/Exclude Source List

Select one of the following options, as appropriate:

  • Include all event sources in the list
  • Exclude all event sources in the list

Event Type Details

This option helps you to configure event details.

Event Types to Monitor

Select one or more of the following event types to use in the filter for monitoring.

  • Critical
  • Error
  • Warning
  • Information
  • Verbose
  • Success_Audit
  • Failure_Audit
  • Others

Consolidate event types when reporting

  • Select this option if you want various types of events (for example, Warning, Information, Error) to be reported by using one parameter, ELMStatus (or ELMNotification if you configured to be notified immediately when an error occurs while defining the Report/Notify option).
  • Clear this check box, if you want to have separate parameters for each event type that can raise alarms independently.

Event ID Details

Click Add button.png button to configure event ID details. 

Windows Event ID(s)

You can select one or more multiple IDs in the following ways:

  • Single event ID. For example: 100
  • Comma-separated list of multiple event IDs. For example: 100,110,120
  • Range of event IDs. For example: 100-120
  • Regular expression. For example: 1[0-5]3

 

Use Event ID as a regular expression

Select this check box if you specified a regular expression in the Windows Event ID(s) field.

Include/Exclude Event ID List

Select one of the following options, as appropriate:

  • Include all event IDs in the list
  • Exclude all event IDs in the list

Event Handling

Choose how to handle your Windows events.

Annotate Graph parameter with event details

Annotates the PATROL parameter graphs associated with this event filter with information about the event. You can display the annotations by placing the cursor over the graph data points.

Annotate Additional Event Data

Select this check box to annotate additional event data for the event in the annotation. You can display the annotations by placing the cursor over the graph data points.

Note: Restart the PATROL Agent to apply the changes.

Write event details to a text parameter

Writes details about the events that occur to a parameter. Depending on which event types the filter monitors, the following parameters are used to report this data:

  • EvRptOfError
  • EvRptOfFailureAudit
  • EvRptOfInformation
  • EvRptOfStatus
  • EvRptOfSuccessAudit
  • EvRptOfWarning
  • EVReportOfOtherTypes
  • EvRptOfNotification: This parameter is active only when you have selected both of the following options:
    Notify immediately and consolidate event types.

Use event details for a recovery action

Saves information about the event in the agent configuration variable RetainEventDescriptions so that you can use this information in recovery actions that you create.

For example, if you create a recovery action that generates an e-mail when the event filter alarms, you could include the event description in the e-mail. If you don’t use recovery actions or don’t plan to use them, deselect this option to limit use of the agent database space.

For more information, see Retained-event-descriptions.

Report multiple events as a single event when the event occurs

Enables event consolidation under the conditions you specify. If X number of events (of any type) occur within X seconds or minutes, they are reported using one parameter.

Only one datapoint is used, but the datapoint annotation contains information about each of the events that occurred.

For more information on event consolidation, see Event-Type-dialog-box.

To return to the default setting (not reporting multiple events as one event and not consolidating events), enter 0 as the number of times that the event occurs.

By default, this value is set to 1.


Time within seconds

Specify the number of seconds that must be used for reporting multiple events as a single event.

By default, this value is set to 0.

Maximum Value: The maximum accepted value for this field is 35791394 minutes.

Enter text automatic or Filter name to Acknowledge Alarm

Specify how you want to acknowledge the alarm raised by the event filter. You can specify one of the following values:

  • automatic: If you specify automatic, then PATROL acknowledges alarms and returns the filter to an OK state if the filter criteria are not met during the most recent collection cycle. In other words, if the events you are monitoring do not occur during the collection cycle, the event filter state is changed back to OK. With this option you are not actively monitoring for alarms, you might not notice when the monitored events occurs because any alarms will be reset during the next collection cycle if the monitored events do not re-occur.
    Note: With this option, PATROL cannot acknowledge the alarm or return the filter to an OK state.
  • filterName: If you specify the filter name, then PATROL changes the filter state from an alarm state to an OK state when the criteria of a second event filter are met. To use this option, you must create an event filter that monitors for the required event and that is configured to notify PATROL immediately when that filter criteria is met, and then specify the filter name in this field.

By default, this value is set to automatic.

Advanced Properties

Click this tab to specify advanced properties for events.

List of Users

Click Add button.png button to configure user details. 

User Name

Specify the user name associated with the events that you want to monitor or exclude from monitoring.

Note: When entering a user that includes special characters that are used in regular expressions, such as a dollar sign ($), a period (.), a parenthesis (), or a slash (\), you must escape each special character with a slash.

For example, if the user name is $Smith, you must enter the category as \$Smith. Event log filter fails to filter events generated with user-based filters entered with a user@domain.com format. Use just the user name (e.g. Administrator) or the Domain\User format (e.g. CIVILWAR\Administrator).

OK

Click to save the configuration.

Cancel

Click to close the dialog.

 

Include/Exclude User List

Select one of the following options, as appropriate:

  • Include all users in the list - Specifies that all of the users in the list are monitored by the event filter. Select this option when you only want to monitor specific users.
  • Exclude all users in the list - Specifies that all the users except those in the list are monitored by the event filter. Select this option when you want to monitor all the users, except for a few specific users, which you want to exclude from the event filter.

Disable Case Sensitivity

If you select this option, the event filter makes filter comparisons in a case-independent manner.

 

List of Categories

Click Add button.png button to provide category details for the events you want to monitor.

Category Name

Specify the category name associated with the events that you want to monitor or exclude from monitoring.

Note: When entering a category that includes special characters that are used in regular expressions, such as a dollar sign ($), a period (.), a parenthesis (), or a slash (\), you must escape each special character with a slash.

For example, if the category is $Smith, you must enter the category as \$Smith. Event log filter fails to filter events generated with user-based filters entered with a user@domain.com format. Use just the user name (e.g. Administrator) or the Domain\User format (e.g. CIVILWAR\Administrator).

OK

Click to save the configuration.

Cancel

Click to close the dialog.

 

Include/Exclude Category List

Select one of the following options, as appropriate:

  • Include all categories in the list - Specifies that all of the categories in the list are monitored by the event filter. Select this option when you only want to monitor specific categories.
  • Exclude all categories in the list - Specifies that all the categories except those in the list are monitored by the event filter. Select this option when you want to monitor all the categories, except for a few specific categories, which you want to exclude from the event filter.

Disable Case Sensitivity

If you select this option, the event filter makes filter comparisons in a case-independent manner.

 

String Details

Click Add button.png button to provide string details associated with the events you want to monitor.

Include String

Specify the string from event description associated with the events that you want to monitor.

When entering a string that includes special characters that are used in regular expressions, such as a dollar sign ($), a period (.), a parenthesis (), or a slash (), you must escape each special character with a slash. For example, if the string is $Error, you must enter the string as \$Error.

OK

Click to save the configuration.

Cancel

Click to close the dialog.

Exclude String

Specify the string from the event description associated with the events.

When entering a string that includes special characters that are used in regular expressions, such as a dollar sign ($), a period (.), a parenthesis (), or a slash (), you must escape each special character with a slash. For example, if the string is $Error, you must enter the string as \$Error.

Disable Case Sensitivity

If you select this option, the event filter makes filter comparisons in a case-independent manner.

OK

Click to save the configuration.

Cancel

Click to close the dialog.

Close

Click this option to save your details

Computer Details

Click Add button.pngto provide details regarding the computers associated with the events that you want to monitor.

 

Computer Name

Specify the computer associated with the events that you want to monitor or exclude from monitoring.

OK

Click to save the configuration.

Cancel

Click to close the dialog.

Include/Exclude User List

 Select one of the following options, as appropriate:

  • Include all computers in the list - Specifies that all of the computers in the list are monitored by the event filter. Select this option when you only want to monitor computers.
  • Exclude all computers in the list - Specifies that all the computers except those in the list are monitored by the event filter. Select this option when you want to monitor all the computers, except for a few specific computers, which you want to exclude from the event filter.

Disable Case Sensitivity

 Select this check box to disable case sensitivity for computer comparison.

Limit Event Subscriptions To

Note: Any modification made to the configuration requires PATROL Agent restart. Only 20 combinations of sources and event IDs are supported.

Event Sources

Enter a comma separated list of event sources.

Note: You must specify the event sources and ids based on the filters that you have configured (using the List of Filters option) for the respective event log.

Event IDs

Enter comma separated list of event ids or event range.

For example: 100,1000-1010,500

 

OK

Click to save the configuration.

Cancel

Click to close the dialog.



 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*