Hi
How do I create a query to show only if computers are reporting back a given event ID or event description?
I want to see which computers are reporting Event ID 1119 and event description "The update failed; see event log"
Solved! Go to Solution.
Hello,
Try this and check whether this is working or not for you:
1)
2)
Click Next and again click on Next and configure the event ID:
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
You can create a new query, type would be threat events, add query type and desired columns, then filter it for the threat event ID
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hello
When i try and look for a filter on Event ID nothing is being displayed
There should be a filter for threat event ID.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hello,
Try this and check whether this is working or not for you:
1)
2)
Click Next and again click on Next and configure the event ID:
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Thanks @vivs , I didn't have my server up to get screenshots 🙂
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: