<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to add Microsoft-Windows-Windows Defender in Log Storage? in Alerting</title>
    <link>https://community.dynatrace.com/t5/Alerting/Adding-Microsoft-Windows-Windows-Defender-in-Log-Storage/m-p/216448#M3601</link>
    <description>&lt;P&gt;Thanks to my colleague&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/63586"&gt;@Ranjeet_Tiwari&lt;/a&gt;&amp;nbsp;it now works. The log storage matcher is changed to&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="McVitas_0-1688030602758.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/12536i56A36706330F4651/image-size/medium?v=v2&amp;amp;px=400" role="button" title="McVitas_0-1688030602758.png" alt="McVitas_0-1688030602758.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and custom log source rule is like this&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="McVitas_1-1688030665347.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/12537i425F30C47C16F303/image-size/medium?v=v2&amp;amp;px=400" role="button" title="McVitas_1-1688030665347.png" alt="McVitas_1-1688030665347.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However I am not very wise from this and it still doesn't make much sense to me :-]&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jun 2023 09:25:06 GMT</pubDate>
    <dc:creator>McVitas</dc:creator>
    <dc:date>2023-06-29T09:25:06Z</dc:date>
    <item>
      <title>Adding Microsoft-Windows-Windows Defender in Log Storage</title>
      <link>https://community.dynatrace.com/t5/Alerting/Adding-Microsoft-Windows-Windows-Defender-in-Log-Storage/m-p/216355#M3600</link>
      <description>&lt;P&gt;Hello, I want to create alert based on certain events from this eventlog, but can't figure out how to make Dynatrace ingest it.&lt;/P&gt;
&lt;P&gt;We have one Log storage configuration rule like this&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="McVitas_0-1687944295051.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/12518i3ED2E75900193924/image-size/medium?v=v2&amp;amp;px=400" role="button" title="McVitas_0-1687944295051.png" alt="McVitas_0-1687944295051.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;and this works and default eventlogs are visible in Log viewer. I tried adding this Microsoft-Windows-Windows Defender/Operational&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="McVitas_1-1687944334824.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/12519i36B0641396E93621/image-size/medium?v=v2&amp;amp;px=400" role="button" title="McVitas_1-1687944334824.png" alt="McVitas_1-1687944334824.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="McVitas_2-1687944384404.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/12520i5475A0891C4B311C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="McVitas_2-1687944384404.png" alt="McVitas_2-1687944384404.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;but nothing comes up. According to &lt;A href="https://www.dynatrace.com/support/help/observe-and-explore/logs/log-monitoring/acquire-log-data/add-log-files-manually-v2#expand--example" target="_self"&gt;this documentation page&lt;/A&gt; I tried adding a full path to the evtx file which is %SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx but this also don't seem to work.&lt;/P&gt;
&lt;P&gt;I tried to add the same in Custom log source configuration like this&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="McVitas_3-1687944747199.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/12521i3AAA15E73DEEC5AB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="McVitas_3-1687944747199.png" alt="McVitas_3-1687944747199.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;but still no events show up even though there are new events happening for example when I disable/enable realtime protection in Windows Security GUI.&lt;/P&gt;
&lt;P&gt;Ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 14:24:07 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Alerting/Adding-Microsoft-Windows-Windows-Defender-in-Log-Storage/m-p/216355#M3600</guid>
      <dc:creator>McVitas</dc:creator>
      <dc:date>2023-07-06T14:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: how to add Microsoft-Windows-Windows Defender in Log Storage?</title>
      <link>https://community.dynatrace.com/t5/Alerting/Adding-Microsoft-Windows-Windows-Defender-in-Log-Storage/m-p/216448#M3601</link>
      <description>&lt;P&gt;Thanks to my colleague&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/63586"&gt;@Ranjeet_Tiwari&lt;/a&gt;&amp;nbsp;it now works. The log storage matcher is changed to&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="McVitas_0-1688030602758.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/12536i56A36706330F4651/image-size/medium?v=v2&amp;amp;px=400" role="button" title="McVitas_0-1688030602758.png" alt="McVitas_0-1688030602758.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and custom log source rule is like this&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="McVitas_1-1688030665347.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/12537i425F30C47C16F303/image-size/medium?v=v2&amp;amp;px=400" role="button" title="McVitas_1-1688030665347.png" alt="McVitas_1-1688030665347.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However I am not very wise from this and it still doesn't make much sense to me :-]&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 09:25:06 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Alerting/Adding-Microsoft-Windows-Windows-Defender-in-Log-Storage/m-p/216448#M3601</guid>
      <dc:creator>McVitas</dc:creator>
      <dc:date>2023-06-29T09:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to add Microsoft-Windows-Windows Defender in Log Storage?</title>
      <link>https://community.dynatrace.com/t5/Alerting/Adding-Microsoft-Windows-Windows-Defender-in-Log-Storage/m-p/217124#M3630</link>
      <description>&lt;P&gt;Thanks for sharing the answer,&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/63414"&gt;@McVitas&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 14:25:28 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Alerting/Adding-Microsoft-Windows-Windows-Defender-in-Log-Storage/m-p/217124#M3630</guid>
      <dc:creator>AgataWlodarczyk</dc:creator>
      <dc:date>2023-07-06T14:25:28Z</dc:date>
    </item>
  </channel>
</rss>

