<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some Columns Missing When Ingesting Windows Event Log &amp;quot;Forwarded Events&amp;quot; (AKA: ForwardedEvents) in Log Analytics</title>
    <link>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/289949#M1490</link>
    <description>&lt;P&gt;Hi, Forwarded Event Logs are not currently supported due to technical limitations. The situation does not look like a trivial fix. Currently there is no expected date for supporting this use case (Forwarded Event Logs). Please negotiate it with our Product Manager&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/44233"&gt;@TomekRybczynski&lt;/a&gt;&amp;nbsp;(internal ticket:&amp;nbsp;OA-56273)&lt;/P&gt;</description>
    <pubDate>Thu, 20 Nov 2025 11:08:21 GMT</pubDate>
    <dc:creator>Joachim_Erdei</dc:creator>
    <dc:date>2025-11-20T11:08:21Z</dc:date>
    <item>
      <title>Some Columns Missing When Ingesting Windows Event Log "Forwarded Events" (AKA: ForwardedEvents)</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/278304#M1341</link>
      <description>&lt;P&gt;We have some database hosts we can't install OneAgent on, so we setup Windows Event Viewer Subscriptions on a remote host that&amp;nbsp;&lt;EM&gt;does&amp;nbsp;&lt;/EM&gt;have OneAgent installed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically, the Windows Event Viewer on the "collector" host (the one that&amp;nbsp;&lt;EM&gt;does&amp;nbsp;&lt;/EM&gt;have OneAgent installed) is subscribed to the Application and System event logs on two Windows Database Servers that &lt;EM&gt;don't&amp;nbsp;&lt;/EM&gt;have OneAgent installed.&amp;nbsp; The collector then collects the logs from those two database servers using the Windows Event Viewer Subscriptions feature and stores them in the "Forwarded Events"&amp;nbsp;log (Full Name is "ForwardedEvents") on the collector host.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I then added that Forwarded Events log as a Custom Windows Log Source in Dynatrace and I see the log entries in Dynatrace.&lt;BR /&gt;&lt;BR /&gt;Great, right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, no... not so great.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For some reason, Dynatrace doesn't collect two important columns, even though they do exist in the actual event log on the collector host:&lt;/P&gt;
&lt;P&gt;"&lt;STRONG&gt;Log&lt;/STRONG&gt;" and "&lt;STRONG&gt;Computer&lt;/STRONG&gt;".&lt;/P&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="36Krazyfists_1-1748558191340.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/28272i749319F623E3743B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="36Krazyfists_1-1748558191340.png" alt="36Krazyfists_1-1748558191340.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Log field tells you which log the particular record came from (either Application or System in our case) and the Computer field tells you which of the two database hosts sent this particular record.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since Dynatrace doesn't collect these two fields, I have no way of doing anything meaningful with these logs...&amp;nbsp; I don't know which hosts they came from nor do I know which original event log they belonged to...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The simple solution would be to create custom Windows Event Logs and have each log for each host sent to their own respective logs in the collector's event viewer, but creating new logs in Windows isn't very straightforward.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;So, is there any way to get Dynatrace to pick up and display those columns?&amp;nbsp; Why doesn't Dynatrace display them?&amp;nbsp; I don't get it...&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 08:05:50 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/278304#M1341</guid>
      <dc:creator>36Krazyfists</dc:creator>
      <dc:date>2025-05-30T08:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Some Columns Missing When Ingesting Windows Event Log "Forwarded Events" (AKA: ForwardedEvents)</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/289758#M1485</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/41155"&gt;@36Krazyfists&lt;/a&gt;,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here is the answer I've found in our internal resources&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV id="C7H2U4M6K-1748870558.352739-thread-list-Thread_1750078890.580809" class="c-virtual_list__item" tabindex="0" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1750078890.580809"&gt;
&lt;DIV class="c-message_kit__background c-message_kit__message c-message_kit__thread_message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--default"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;EM&gt;OneAgent only extracts the limited list of attributes from Windows Event Logs. You can find it here:&lt;/EM&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="c-message_kit__attachments"&gt;
&lt;DIV class="c-message_attachment" data-qa="message_attachment_default"&gt;
&lt;DIV class="c-message_attachment__body"&gt;
&lt;DIV class="c-message_attachment__row"&gt;&lt;EM&gt;&lt;SPAN class="c-message_attachment__title" data-qa="message_attachment_title"&gt;&lt;A class="c-link c-message_attachment__title_link" href="https://docs.dynatrace.com/docs/shortlink/lma-add-log-from-windows-events#attributes" target="_blank" rel="noopener noreferrer" data-qa="message_attachment_title_link"&gt;Windows event logs — Dynatrace Docs&lt;/A&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV class="c-message_attachment__row"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="C7H2U4M6K-1748870558.352739-thread-list-Thread_1750079081.355949" class="c-virtual_list__item" tabindex="-1" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1750079081.355949"&gt;
&lt;DIV class="c-message_kit__background c-message_kit__background--hovered c-message_kit__message c-message_kit__thread_message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover c-message_kit__hover--hovered" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;EM&gt;Although starting with agent version 317 there is possibility to ingest all the data from Windows Event Logs in the&amp;nbsp;&lt;STRONG data-stringify-type="bold"&gt;User Data&lt;/STRONG&gt;&amp;nbsp;or&amp;nbsp;&lt;STRONG data-stringify-type="bold"&gt;Event Data&lt;/STRONG&gt;&amp;nbsp;branches (depending on availability).&lt;/EM&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 18 Nov 2025 14:22:08 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/289758#M1485</guid>
      <dc:creator>MaciejNeumann</dc:creator>
      <dc:date>2025-11-18T14:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Some Columns Missing When Ingesting Windows Event Log "Forwarded Events" (AKA: ForwardedEvents)</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/289949#M1490</link>
      <description>&lt;P&gt;Hi, Forwarded Event Logs are not currently supported due to technical limitations. The situation does not look like a trivial fix. Currently there is no expected date for supporting this use case (Forwarded Event Logs). Please negotiate it with our Product Manager&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/44233"&gt;@TomekRybczynski&lt;/a&gt;&amp;nbsp;(internal ticket:&amp;nbsp;OA-56273)&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2025 11:08:21 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/289949#M1490</guid>
      <dc:creator>Joachim_Erdei</dc:creator>
      <dc:date>2025-11-20T11:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Some Columns Missing When Ingesting Windows Event Log "Forwarded Events" (AKA: ForwardedEvents)</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/290011#M1491</link>
      <description>&lt;P&gt;Hello, would there be any know possible workaround on this topic please?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 09:49:01 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/290011#M1491</guid>
      <dc:creator>JR79</dc:creator>
      <dc:date>2025-11-21T09:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Some Columns Missing When Ingesting Windows Event Log "Forwarded Events" (AKA: ForwardedEvents)</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/290052#M1492</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/44233"&gt;@TomekRybczynski&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/11445"&gt;@marcin_okraszew&lt;/a&gt;&amp;nbsp;Are you aware if some solution based on Generic Ingest can support this use case?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 11:56:58 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Some-Columns-Missing-When-Ingesting-Windows-Event-Log-quot/m-p/290052#M1492</guid>
      <dc:creator>Joachim_Erdei</dc:creator>
      <dc:date>2025-11-21T11:56:58Z</dc:date>
    </item>
  </channel>
</rss>

