I am not sure if this is the correct place to post this, but consider this a feature request as much as a tech question (about Snare).
PRTG does a great job, however one point of functionality I absolutely need is for the Windows Event Log sensors to track message history the way that the Syslog sensor does.
I need to audit certain events for compliance purposes. For example I need to audit the security event log for successful account lockouts (event 4740) and be able to report on these lo
At the moment I have set up a event log to syslog forwarder which will forward the required events from the servers to PRTG and shows the message. which is working ok so far, but it's a bit clunky, especially since I haven't been able to get Snare working with the PRTG syslog server, and have had to rely on Datagram SyslogAgent which is a bit more limited.
It seems like the functionality is there already built in, you would just need to merge the functionality of the syslog with the event log sensors. It would be a feature a lot of people would appreciate I am sure.
Barring that, help getting PRTG to pick up the syslog forwards from Snare would be great.