[GH-ISSUE #226] allow any event log channel to be queried #140

Closed
opened 2026-03-02 02:13:52 +03:00 by kerem · 3 comments
Owner

Originally created by @bbrendon on GitHub (Jan 1, 2021).
Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/226

Is it possible to change the event log query to "Event log channel" and allow us to write it in?

For example a channel such as:
Microsoft-Windows-Windows Defender/Operational

The regular "System" event log is the System channel

image

Originally created by @bbrendon on GitHub (Jan 1, 2021). Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/226 Is it possible to change the event log query to "Event log channel" and allow us to write it in? For example a channel such as: `Microsoft-Windows-Windows Defender/Operational` The regular "System" event log is the `System` channel ![image](https://user-images.githubusercontent.com/6364477/103431554-93110880-4b86-11eb-9985-1571d8581f5e.png)
kerem closed this issue 2026-03-02 02:13:53 +03:00
Author
Owner

@dinger1986 commented on GitHub (Jan 1, 2021):

I achieved this using powershell to query the event viewer and report back

<!-- gh-comment-id:753233280 --> @dinger1986 commented on GitHub (Jan 1, 2021): I achieved this using powershell to query the event viewer and report back
Author
Owner

@dinger1986 commented on GitHub (Feb 21, 2021):

@bbrendon is this ok to close as can be achieved via powershell

<!-- gh-comment-id:782931653 --> @dinger1986 commented on GitHub (Feb 21, 2021): @bbrendon is this ok to close as can be achieved via powershell
Author
Owner

@sadnub commented on GitHub (May 29, 2021):

We don't plan on adding new checks or expanding existing checks since everything can essentially be accomplished with script checks. Check examples can be created and added to community script to offload the task of creating the script. I believe there might be a few that are there.

<!-- gh-comment-id:850768837 --> @sadnub commented on GitHub (May 29, 2021): We don't plan on adding new checks or expanding existing checks since everything can essentially be accomplished with script checks. Check examples can be created and added to community script to offload the task of creating the script. I believe there might be a few that are there.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/tacticalrmm#140
No description provided.