The Windows Event Log can be monitored by PRTG (Event Log (Windows API) Sensor or WMI Event Log Sensor). You can either filter by including or excluding. That is OK. My customer would like to extend the sensor (or if you want have a new sensor). The extension makes it more granular.
This sensor would allow you to trigger an alarm when an entry occurs x (value should be defined by the end user) over a certain amount of time (value should be defined by the user)
The background is that an event with a specific ID only is interesting when occurs x times during a specific amount of time (say 100 seconds or 60 minutes). In case you have 15 event of ID 123 during 2 minutes, you would like the status to be changing. Specially events in the security log file need attention in this type of cases.
Please vote up if you have an application for this and see the benefits!