Not receiving all Windows Event Log Streams

Answered

Comments

2 comments

  • Official comment
    Avatar
    Paul Le Page

    Hi Bob,

    I can see you have a ticket raised with support for this issue - I think progressing that will be the best way to get your query resolved.

    If you have configured all streams to be collected, that is what should be happening. However it is possible we do not have parsers for the particular messages that you are interested in. You can view unparsed messages in the log search interface by setting "Message Type" to "Does Not Exist." You can still perform full text search on the unparsed messages, eg. "Message" contains "DHCP"

    If parsers are required for your specific use case, you can request parser creation by our content team via support - they will send you a form to complete. There is no charge for this service - you can find out more about requesting parsers in the knowledge base here: https://support.alertlogic.com/hc/en-us/articles/115000391187-How-can-I-request-for-my-logs-to-be-parsed-

     

  • Avatar
    Abby Kincer

    Bob -

    Looks like the community didn’t have much in the way of advice for you on this, so I’m going to pull in some experts to see if they can help!

Please sign in to leave a comment.