Jun 25 2020
04:55 PM
- last edited on
Apr 08 2022
10:30 AM
by
TechCommunityAP
Jun 25 2020
04:55 PM
- last edited on
Apr 08 2022
10:30 AM
by
TechCommunityAP
I have some on-premise servers where I would like to send specific Windows event log IDs to a Log Analytics workspace. I see I can download the MMA agent. How to configure it to only send specific Event IDs?
Jun 28 2020 06:37 AM
@shockotechcom I don't think you can send specific event log IDs.
You can send specific event logs (Application, System etc) and specific types ie Error, Warning & Info but not an actual ID.
You would normally then use Kusto queries on the logs ingested into Log Analytics to filter for specific ID's and then trigger alerts/runbooks/logic apps etc.
Feb 26 2021 07:45 AM
Feb 27 2021 03:21 PM
Mar 01 2021 01:04 AM
Mar 01 2021 06:29 AM