Event Log Check Reference
Configuration options for the Windows Event Log check
Written By Erdinc Akay
Last updated About 2 months ago
Event Log Check Reference
Configuration options for the Windows Event Log check
The event log check scans the Windows Event Log for entries at or above a specified severity level and raises an alert when the count exceeds a threshold.
Configuration fields
Severity levels
Metrics collected
- Total count of retrieved events across the selected logs, up to the configured maximum
- Individual matching entries (source, event ID, message, timestamp)
- List of logs that were requested but could not be read
Platform support
Notes
- The check runs every 15 minutes by default. Interval is a check-level setting and is not part of the per-assignment configuration.
- Set the lookback period to match or exceed the check interval to avoid gaps between runs.
- Common noisy sources to exclude:
ESENT,DistributedCOM. - By default the check retrieves up to 50 events per log (configurable via Max events per log) to keep the result payload manageable. If you need more detail, open the device's Event Log view in the toolbox to browse entries directly — or query the event log via the remote terminal.
See also: Configure an Event Log Check