{"id":214,"date":"2007-08-11T21:31:11","date_gmt":"2007-08-11T19:31:11","guid":{"rendered":"http:\/\/contoso.se\/blog\/?p=214"},"modified":"2011-04-14T08:25:30","modified_gmt":"2011-04-14T06:25:30","slug":"how-to-create-a-correlated-windows-event-unit-monitor","status":"publish","type":"post","link":"http:\/\/contoso.se\/blog\/?p=214","title":{"rendered":"How to Create a Correlated Windows Event Unit Monitor"},"content":{"rendered":"<p>In this post I will show how to\u00c2\u00a0create a monitor that check for one event and if there is not another event within a specified timeframe minute from the first event, the monitor will generate an alert. I will reset the monitor with time, 3 minutes, but you can choose to reset the monitor with for example a third log event.<\/p>\n<p>1. Start the console<br \/>\n2. Go to Authoring, expand management pack objects and click Monitors<br \/>\n3. Click Scope and\u00c2\u00a0select Windows Computer,\u00c2\u00a0click OK<br \/>\n4. Expand Windows Computers, expand Entity Health, right-click Availability and choose to create a new unit monitor<br \/>\n5. Create a unit monitor &#8211; Monitor Type: Choose Windows Events\/Correlated Missing Event Detection\/Timer Reset, click Next<br \/>\n6. Create a unit monitor &#8211; General: Input a name and a description, click Next<br \/>\n7. Create a unit monitor &#8211; Missing Event Log Name A: Input the event log name of the first event, click Next<br \/>\n8. Create a unit monitor &#8211; Build Missing Event Log Expression for A: Input event ID and event source, in my example it will be event id 1000 and event source EventCreate. Click Next<br \/>\n9. Create a unit monitor -\u00c2\u00a0Missing Event Log Name\u00c2\u00a0B: Input the event log name of the second event, click Next<br \/>\n10. Create a unit monitor &#8211; Build Missing Event Log Expression for B: Input event ID and event source, in my example it will be event id 2000 and event source EventCreate. Click Next<br \/>\n11. Create a unit monitor &#8211; Configure Correlation:<br \/>\nCorrelation interval: 1 Minutes<br \/>\nCorrelation Details: The last occurrence of A with the configured occurrence of B in chronological order<br \/>\nClick Next<br \/>\n12. Create a unit monitor &#8211; Auto Reset Timer: In my example I will specify 3 minutes, click Next<br \/>\n13. Create a unit monitor &#8211; Configure Health: Click Next<br \/>\n14. Create a unit monitor &#8211; Configure Alerts: Check &#8220;Generate alerts for this monitor&#8221; and then click Create<\/p>\n<p>If I only get a event ID 2000 and no event ID 1000 there will be a alert. If I get event ID 2000 and event ID 1000 within 1 minute there will be no alert. You can change the correlation configuration in any way you want, for example in which order the events must be generated.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this post I will show how to\u00c2\u00a0create a monitor that check for one event and if there is not another event within a specified timeframe minute from the first event, the monitor will generate an alert. I will reset the monitor with time, 3 minutes, but you can choose to reset the monitor with &hellip; <a href=\"http:\/\/contoso.se\/blog\/?p=214\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[19],"tags":[],"_links":{"self":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/214"}],"collection":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=214"}],"version-history":[{"count":2,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/214\/revisions"}],"predecessor-version":[{"id":2331,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/214\/revisions\/2331"}],"wp:attachment":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=214"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=214"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}