I want to set up a filter with the Windows-Api Eventlog-Sensor. I set it up in protocol for Windows Security Protocol and in type for Security Audit Errors.
Without filtering I get new entries in the monitoring tool, when a failure happens.
When I apply any filter, e.g. eventId or just a string in the message filter (and these strings actually are there in the event protocol messages) I get no event logged by the prtg monitor.
Sometimes when I reset the filter also without filter nothing is logged anymore by prtg. I have to apply a new sensor with the same configuration and this one works (just without any filter).
Add comment