cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Adding Microsoft-Windows-Windows Defender in Log Storage

McVitas
Participant

Hello, I want to create alert based on certain events from this eventlog, but can't figure out how to make Dynatrace ingest it.

We have one Log storage configuration rule like this

McVitas_0-1687944295051.png

and this works and default eventlogs are visible in Log viewer. I tried adding this Microsoft-Windows-Windows Defender/Operational

McVitas_1-1687944334824.png

like this:

McVitas_2-1687944384404.png

but nothing comes up. According to this documentation page I tried adding a full path to the evtx file which is %SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx but this also don't seem to work.

I tried to add the same in Custom log source configuration like this

McVitas_3-1687944747199.png

but still no events show up even though there are new events happening for example when I disable/enable realtime protection in Windows Security GUI.

Ideas?

2 REPLIES 2

McVitas
Participant

Thanks to my colleague @Ranjeet_Tiwari it now works. The log storage matcher is changed to

McVitas_0-1688030602758.png

and custom log source rule is like this

McVitas_1-1688030665347.png

However I am not very wise from this and it still doesn't make much sense to me :-]

Thanks for sharing the answer, @McVitas 🙂 

When passion meets people magic and innovation happen.

Featured Posts