<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to find all possible event ID’s for a given event source</title><link>http://blogs.technet.com/kevinholman/archive/2009/02/16/how-to-find-all-possible-event-id-s-for-a-given-event-source.aspx</link><description>I recently got this question from a customer… and felt it would be good to blog about this. The customer wants to create an Alert, anytime there is a event in the System event log, from a USER32 event source: &amp;#160; HOWEVER – it is a best practice in</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Using Event Description as criteria for a rule</title><link>http://blogs.technet.com/kevinholman/archive/2009/02/16/how-to-find-all-possible-event-id-s-for-a-given-event-source.aspx#3204291</link><pubDate>Thu, 19 Feb 2009 02:16:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3204291</guid><dc:creator>Kevin Holman's OpsMgr Blog</dc:creator><description>&lt;p&gt;When we write rules and monitors to look at events in the event log.... typically the most common criteria&lt;/p&gt;
</description></item><item><title>Authoring rules for Windows 2008 events, and how to cheat</title><link>http://blogs.technet.com/kevinholman/archive/2009/02/16/how-to-find-all-possible-event-id-s-for-a-given-event-source.aspx#3206391</link><pubDate>Wed, 25 Feb 2009 04:56:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3206391</guid><dc:creator>Kevin Holman's OpsMgr Blog</dc:creator><description>&lt;p&gt;So…. with the introduction of Server 2008 into OpsMgr… as a monitored agent, you might need to re-evaluate&lt;/p&gt;
</description></item></channel></rss>