rul_adc_winlog.

On all Windows machines, from the earliest 3.1 Workstation to the current operating systems, there are always at least three Windows Event Logs, namely Application, Security, and System.

Other more recent operating systems have up to three additional Event Logs.

Argent enables you to be alerted on any and all anomalies on your Windows servers and desktops.

The Windows Event Rules are configured using the Basic tab of the Rule definition interface.

Step 1: Select Event Logs and Optional Severity and Time Windows

Here, you see the Event Logs to be consolidated, and what severity levels you’re interested in.

Step 2: Set Optional Rule Filters

See Also: Rule Filters

Step 3: Set Optional Rule Alerts

See Also: Rule Alerts