Forum Discussion

shockotechcom's avatar
Iron Contributor
Jun 25, 2020

Send Windows Event Logs Into Log Analytics Workpace

I have some on-premise servers where I would like to send specific Windows event log IDs to a Log Analytics workspace. I see I can download the MMA agent. How to configure it to only send specific Event IDs?

  • JK_UK's avatar
    Brass Contributor

    shockotechcom I don't think you can send specific event log IDs.

    You can send specific event logs (Application, System etc) and specific types ie Error, Warning & Info but not an actual ID.

    You would normally then use Kusto queries on the logs ingested into Log Analytics to filter for specific ID's and then trigger alerts/runbooks/logic apps etc.

