Hi, after trying out the Syslog sensor for our non-Windows devices I'd also like to centralise our Windows logs so PRTG becomes the central store for logging data.
I've configured a Win API Eventlog sensor which looks fine in terms of capturing the Event logs and I can see them coming up in PRTG.
Problem is I can't seem to find any way to search through the data to do any analysis on it; for example searching through a date range for log events relating to a particular user.
Is this possible or is the sensor only good for reporting volume of events, rather than any sort of detailed analysis on historic data retained?
Hi there,
Your assumption is basically correct, the sensor is all about volume, it's not intended to keep track of all the details and does not save those messages in order to analyze them and alike. Basically almost all of PRTG's sensors are more focussed on processing numbers and are less suited to act on textual information.
Kind regards,
Erhard
Mar, 2018 - Permalink