Oh okay. I believe I see the problem. After Logon Type: there are a number of space, you need this to match the amount shown in the event. So, you will need to use something like what I attached -- just copy and paste the event into notepad, then copy and paste the "Logon Type: 10" (or however many spaces) into the Rules Expression editor. Since it doesn't see those spaces, it's not processing the event properly.
Windows Event Log - Rules Expression Editor Help
I am struggling with the Rules Expression Editor and Windows Event Logs
I can't seem to get the syntax right to log ONLY RDP Logon/Logoff events
I have the event IDs correct, when I apply my passive monitor it works, but I want I only want to get events with the words "Logon Type: 10" in the event, this means that it is a RDP session.
Conditions are Event ID = 4624 Or Event ID = 4634, this works fine, as soon as I add (Logon Type:10) to the expression editor I get no events, my expression is obviously wrong
I have scoured the Internet looking for examples, the only one I found on the WUG FAW was this
but I can't make it work
Any help is greatly appreciated
- 1,053 views
- 1 version
- 21 replies
- 4 followers
- Post Date:
- April 9, 2012
- Posted By:
- Luke Draper
About this forum
- 142k views
- 2222 topics
- 55 followers
Post questions and find answers for all things related to the Standard and Premium Editions of WhatsUp gold.