I am setting up a watch group for an NT event log, and I am ready to define a key. How many of the fields do I need to specify?
An NT event log key normally contains six fields: the Event Type, the Source, the Category ID, the Event ID, the User, and the Computer. In most cases, the Source and the Event ID are all that is required to uniquely define an event. For example, event ID 6005 from the EventLog source is always “The Event log service was started”. However, and this is something you need to check, some applications that generate events use the same event source and ID, but change the text of the message. In this case, use the seventh field, and look for an actual piece of text.
Related Questions
- I am setting up a watch group for a text log to look for two pieces of text. What is the difference between adding a second text key, versus using the second field in the first text key?
- I am setting up a watch group for an NT event log, and I am ready to define a key. How many of the fields do I need to specify?
- If there isn a Neighbourhood Watch group locally, how can I go about setting one up?