Important Notice: On February 29th, this community was put into read-only mode. All existing posts will remain but customers are unable to add new posts or comment on existing. Please feel to join our Community Discord for any questions and discussions.

Scan a specific Event Log ID

Hi All,

We are currently attaching all our domain PC's to the ATP portal. As part of this work i have been asked to run a report on all Machines showing a specific event log. Here is the following information i need to report on -

%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-SENSE%4Operational.evtx

within the event "Microsoft-Windows-SENSE%4Operational.evtx" is the event ID number 4

This event ID states a successful communication to the ATP portal, indicating all is well

is it possible to crate a scan against a specific event ID against a specific Event log?

If so how?

Thank youenter image description here

2

Comments

0 comments