Add Windows Event Log monitoring to a service template
The Windows event log is a record of all events - information, warnings and errors - produced by a Windows computer. The N-able N-central Windows Event Log Monitoring service enables you to monitor this log and filter important notifications.
Add monitoring to a service template with filters to retrieve only the information you need.
- In the right navigation menu, click Administration > Service Management > Service Templates
- Select a template from the list
- Select Windows Event Log from the Service drop-down menu and click Add Service
- Edit the Name to identify this service instance
- In the Details section, select the event and error details that you want monitored:
Option to Monitor:
You can select Use Default Values to configure the service template service parameters with system default values, or deselect to use custom values for the following parameters
Option Error Information Warning Failure Success Security - - - Application - - System - - DNS Server - - File Replication Service - - Directory Service - - - Generate a Notification when an event is detected: Yes, No or Use Default Values
- Scan Interval: The time (in minutes) between each scan, or Use Default Values
- Service Identifier: A unique name that can be used to define an individual instance of the Windows Event Log service (included in email notifications and on service-related displays)
- Event Conditions (Optional): Select between one of the two following options for N-central to recognize the event:
- All child conditions must be satisfied (AND)
- At least one child condition must be satisfied (OR)
Then select the child condition(s) from:
- Event ID Include List
- Event ID Exclude List
- Event Source Include Filter
- Event Source Exclude Filter
- Event Description Regex Filter
The use of AND or OR logic for N-able N-central here can be used to create precise notifications from events. For more information, see Reducing notification noise in Windows event logs.
- Click Save
Always enter a unique name so that you know what the service is from the status tab of a device. This is important for service templates that have multiple instances of the service.
The service is added to the template. Notifications of the events configured will appear.