<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx</link><description>When we write rules and monitors to look at events in the event log.... typically the most common criteria are Event ID and Source.&amp;#160; We also have a list of other common event properties to choose from: However, this list doesn't always work.&amp;#160;</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3113029</link><pubDate>Thu, 28 Aug 2008 01:12:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3113029</guid><dc:creator>Mike</dc:creator><description>&lt;p&gt;When I try this, I get:&lt;/p&gt;
&lt;p&gt;Alert description: {0} {1} {2} {3} {4}&lt;/p&gt;
</description></item><item><title>Using OpsMgr to see which servers have not been logged on to via RDP</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3117842</link><pubDate>Thu, 04 Sep 2008 00:46:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3117842</guid><dc:creator>Kevin Holman's OpsMgr Blog</dc:creator><description>&lt;p&gt;This came up in a discussion group.... and while it maybe not be all that interesting of a topic....&lt;/p&gt;
</description></item><item><title>re: Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3128359</link><pubDate>Thu, 25 Sep 2008 22:15:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3128359</guid><dc:creator>Stephan Lalonde</dc:creator><description>&lt;p&gt;This does not work. &amp;nbsp;It fails to filter out the correct information and when you specify these parameters as part of the alert description to see which one is which, you get {0} {1} {2} {3} {4} etc... &amp;nbsp;As previously stated!!!&lt;/p&gt;
</description></item><item><title>re: Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3131974</link><pubDate>Fri, 03 Oct 2008 19:32:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3131974</guid><dc:creator>Will Kaiser</dc:creator><description>&lt;p&gt;Just to elaborate, the above posts are ultimately correct.&lt;/p&gt;
&lt;p&gt;The log parser does indeed give you parameter numbers for an event log, and you can indeed build a rule based on that which will fire off appropriately.&lt;/p&gt;
&lt;p&gt;The problem is that when you use parameters you apparently cannot pull other data from the event log into the alert description.&lt;/p&gt;
&lt;p&gt;So in my case, I'm looking for 'logon type: 10' in a particular security event log. &amp;nbsp;I used the log parser to discover that '10' is parameter 4. &amp;nbsp;I built my rule to watch for parameter 4 is equal to 10. &amp;nbsp;It works, an alert is generated when that specific log is created, HOWEVER, when I attempt to display information from that event log in the alert description, the values are '{1} {2}' etc instead of the actual data from the alert, which renders this approach worthless.&lt;/p&gt;
&lt;p&gt;Note that I have roughly 40 other rules that watch security event logs like this, and I have created a template that I paste into the body of alert that provides the alert description as well as the alerting source in a readable fashion. &amp;nbsp;That template works with all other event log based rules and passes the event description into alert body successfully. &amp;nbsp;Using the above approach, I now only get '{1} {2} {3}...'.&lt;/p&gt;
&lt;p&gt;Any thoughts on this? &amp;nbsp;Is there a way to translate the {1} values into actual data from the event?&lt;/p&gt;
</description></item><item><title>re: alert description not working?</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3131999</link><pubDate>Fri, 03 Oct 2008 20:47:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3131999</guid><dc:creator>kevinhol</dc:creator><description>&lt;p&gt;I dont know what to say - it works fine for me.&lt;/p&gt;
&lt;p&gt;I would start by testing this - dont paste in anything - just use the flyouts... and add JUST PARAMETER 1.... using the UI controls. &amp;nbsp;Start with a blank alert description, click the ellipsis, click data, specify parameter 1 only, click ok. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Then - give that enough time to propogate down to the agent - then test the event... &amp;nbsp;then go back and add in all the appropriate parameters. &amp;nbsp;It works fine for me... I did get it to mess up once, but now I cannot repro it. It might have something about the alert description not liking a pasted in text dump from html... or the spaces, or the &amp;lt;BR /&amp;gt; in some combination. &amp;nbsp;I cannot repro it not working, however....&lt;/p&gt;
</description></item><item><title>Authoring rules for Windows 2008 events, and how to cheat</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3206390</link><pubDate>Wed, 25 Feb 2009 04:56:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3206390</guid><dc:creator>Kevin Holman's OpsMgr Blog</dc:creator><description>&lt;p&gt;So…. with the introduction of Server 2008 into OpsMgr… as a monitored agent, you might need to re-evaluate&lt;/p&gt;
</description></item><item><title>OpsMgr 2007: How to get alerts for domain group membership changes</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3256322</link><pubDate>Thu, 18 Jun 2009 18:32:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3256322</guid><dc:creator>The Operations Manager Support Team Blog</dc:creator><description>&lt;p&gt;Using System Center Operations Manager 2007, you want to get an alert for any change in the domain admin&lt;/p&gt;
</description></item><item><title>re: Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3264944</link><pubDate>Wed, 15 Jul 2009 20:22:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3264944</guid><dc:creator>Roger</dc:creator><description>&lt;p&gt;I am having trouble triggering on the User Name for 531 or 539 security events. The unit monitor works fine if I don't specify an AND User Name condition.&lt;/p&gt;
&lt;p&gt;Here is my log parse output&lt;/p&gt;
&lt;p&gt;C:\Documents and Settings\rcline&amp;gt;&amp;quot;C:\Program Files (x86)\Log Parser 2.2\LogParse&lt;/p&gt;
&lt;p&gt;r.exe&amp;quot; &amp;quot;select top 1 Strings AS Parameters FROM security where EventID=531&amp;quot;&lt;/p&gt;
&lt;p&gt;Parameters&lt;/p&gt;
&lt;p&gt;--------------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;-----------&lt;/p&gt;
&lt;p&gt;scomsql|ACEINA|4|Advapi &amp;nbsp;|Negotiate|USSBYSCOM302|USSBYSCOM302$|ACEINA|(0x0,0x3E7&lt;/p&gt;
&lt;p&gt;)|912|-|-|-&lt;/p&gt;
&lt;p&gt;Here is my unit monitor Event Expression&lt;/p&gt;
&lt;p&gt;( ( Parameter 1 Contains scomsql ) AND ( ( Event ID Equals 539 ) OR ( Event ID Equals 531 ) ) ) &lt;/p&gt;
&lt;p&gt;What am I missing here ?&lt;/p&gt;
</description></item><item><title>re: Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3274761</link><pubDate>Tue, 18 Aug 2009 22:01:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3274761</guid><dc:creator>Andrew Blumhardt</dc:creator><description>&lt;p&gt;I'm currently using a dummy rule to expose the parameter information for a given event using SCOM alert description criteria. For example:&lt;/p&gt;
&lt;p&gt;$Data/Params/Param[1]$&lt;/p&gt;
&lt;p&gt;$Data/Params/Param[2]$&lt;/p&gt;
&lt;p&gt;$Data/Params/Param[3]$&lt;/p&gt;
&lt;p&gt;$Data/Params/Param[4]$&lt;/p&gt;
&lt;p&gt;$Data/Params/Param[5]$&lt;/p&gt;
&lt;p&gt;Now I just have to wait for my target alert to trigger to determine the parameters I need. Hope this helps. Thanks, Andrew&lt;/p&gt;
</description></item><item><title>re: Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3275511</link><pubDate>Fri, 21 Aug 2009 08:38:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3275511</guid><dc:creator>Colin</dc:creator><description>&lt;p&gt;I require all event parameters stored into the datawarehouse. &amp;nbsp;How to achieve this?&lt;/p&gt;
</description></item><item><title>re: Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3297870</link><pubDate>Wed, 02 Dec 2009 19:00:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3297870</guid><dc:creator>RonBen</dc:creator><description>&lt;p&gt;I have this working if I'm only searching for 1 value in Param 1. The below query does not work. Is there something I'm missing?&lt;/p&gt;
&lt;p&gt;( ( Event ID Equals 644 ) AND ( Event Source Equals Security ) AND ( ( Parameter 1 Contains scomusr ) OR ( Parameter 1 Contains tonyh99 ) ) ) &lt;/p&gt;
&lt;p&gt;Ron&lt;/p&gt;
</description></item><item><title>re: Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2008/04/22/using-event-description-as-criteria-for-a-rule.aspx#3297882</link><pubDate>Wed, 02 Dec 2009 20:01:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3297882</guid><dc:creator>kevinhol</dc:creator><description>&lt;p&gt;the problem may be using &amp;quot;contains&amp;quot;.&lt;/p&gt;
&lt;p&gt;Have you tried using a &amp;quot;matches wildcard&amp;quot; or &amp;quot;matches regular expression&amp;quot; ?&lt;/p&gt;
</description></item></channel></rss>