[GH-ISSUE #996] Feature Request: Event Log Check can only use Application, System and Security #604

Closed
opened 2026-03-02 02:17:37 +03:00 by kerem · 2 comments
Owner

Originally created by @JSuenram on GitHub (Feb 28, 2022).
Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/996

Consider you want to monitor Eventlog vor NTLM-Auditing.
You need to look in "Microsoft-Windows-NTLM/Operational" which is not Possible with Event-Log-Check at the moment.

There are about 150 other EventLogs which are not written to Application/System or Security....
Currently you can not use them in TRMM.

Originally created by @JSuenram on GitHub (Feb 28, 2022). Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/996 Consider you want to monitor Eventlog vor NTLM-Auditing. You need to look in "Microsoft-Windows-NTLM/Operational" which is not Possible with Event-Log-Check at the moment. There are about 150 other EventLogs which are not written to Application/System or Security.... Currently you can not use them in TRMM.
kerem closed this issue 2026-03-02 02:17:37 +03:00
Author
Owner

@dinger1986 commented on GitHub (Feb 28, 2022):

you can with powershell, can look at the defender checks for reference

<!-- gh-comment-id:1054180681 --> @dinger1986 commented on GitHub (Feb 28, 2022): you can with powershell, can look at the defender checks for reference
Author
Owner

@silversword411 commented on GitHub (Mar 9, 2022):

You can use powershell to query any event log. Use this as example:
https://github.com/amidaware/community-scripts/blob/main/scripts/Win_Defender_Status_Report.ps1

Closing

<!-- gh-comment-id:1063376127 --> @silversword411 commented on GitHub (Mar 9, 2022): You can use powershell to query any event log. Use this as example: https://github.com/amidaware/community-scripts/blob/main/scripts/Win_Defender_Status_Report.ps1 Closing
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/tacticalrmm#604
No description provided.