
#ENDING A WINDOWS INSTALLER TRANSACTION EVENT ID 1042 KEYGEN#

|Sis|RecordNumber(Sis()siS)=siS=26457-Sis-UNKNOWN_PERF_COUNTER_TYPE 15:15:30,282 (SingleProcess.java:264) DEBUG - siS]:Sis:Category(Sis()siS)=siS=102-Sis-UNKNOWN_PERF_COUNTER_TYPE|Sis|ComputerName(Sis()siS)=siS=xxxxx-Sis-UNKNOWN_PERF_COUNTER_TYPE|Sis|EventCode(Sis()siS)=siS=102-Sis-UNKNOWN_PERF_COUNTER_TYPE|Sis|EventType(Sis()siS)=siS= -Sis-UNKNOWN_PERF_COUNTER_TYPE|Sis|InsertionStrings(Sis()siS)=siS=\GoogleUpdateTaskMachineUA, NT AUTHORITY\SYSTEM, " instance of the "\GoogleUpdateTaskMachineUA" task for user "NT AUTHORITY\SYSTEM".-Sis-UNKNOWN_PERF_COUNTER_TYPE 15:15:30,282 (SingleProcess.java:264) DEBUG - WQL: SELECT Type,EventType,TimeGenerated,SourceName,Category,RecordNumber,ComputerName,EventCode,Message,InsertionStrings FROM Win32_NTLogEvent WHERE Logfile='Microsoft-Windows-TaskScheduler/Operational' AND RecordNumber>=26457 15:15:30,282 (SingleProcess.java:264) DEBUG - Successful local logon as SXXX īelow is the debug log and attached the config screenshot.


I am able to add the remote server and select the added event log, source and event id that needs to be monitored as mentioned in the documentation but I dont get alert triggered. I have added the custom event log name in the preferences section. I have a request to monitor specific event ids from non generic event logs (application,security,system and setup) using Sitescope 2020.05.
