You are hereSupport / Ask The Community / Windows Event Log Alerts With Same Event ID and Different Sources

Windows Event Log Alerts With Same Event ID and Different Sources


4 replies [Last post]
mtittle
Offline
Joined: 05/21/2010

When setting up an alert based on a Windows Event ID Code, is there a way to also specify the Event Source that the Windoows Event ID must come from? For example, Windows Event ID 1126 can have two possible sources--Active Directory and MSExchangeSRS. If I only want an alert for 1126/Active Directory, is there a a way to specify the Active Directory source in the Alert configuration?

Susan - Heroix
Offline
Joined: 10/16/2009
There isn't a way to alert based on Event Log Source

However - we have submitted an enhancement request for this, and I'm working on a modification to make the source an available field for alerts. I'll post an update as soon as I either hear back from development, or I've got a modification.

N Johnston
Offline
Joined: 09/04/2011
We have the same problem

It's been a while. Is this fixed in any recent version, or planned to be fixed?

Thanks

Susan - Heroix
Offline
Joined: 10/16/2009
Workaround for same Event ID, different sources

This hasn't made it in to the product yet, but there is a workaround:

  1. Register a WindowsEventLog collection set up as follows:
    • Enter a unique name for the Instance (e.g. PriorityEvents)
    • Enter the Event ID you want, and select Allow
    • Enter the Source you want and select Allow
    • Select the applicable severities for the Events
  2. Make sure the appropriate severities are listed in the TypeList field for WindowsEventLog in Monitoring >> Manage Rules >> WindowsEventLog
  3. Create an Action rule or Correlated Event for the WindowsEventLog that only looks at the Instance name you set up for the Source/Event ID combination (PriorityEvents in the example)

 
If you run into any problems with this, or have any questions, please send an update,

Thanks,
Susan

Olaf S.
Offline
Joined: 02/14/2011
Hi,we would very much

Hi,

we would very much appreciate this feature as well. Currently we are rewriting eventlog messages to give them a more unique event-ID based on the event source and severity.

kind regards
Olaf