Cannot monitor DELL hardware event logs through ntevl probe

book

Article ID: 130090

calendar_today

Updated On:

Products

DX Infrastructure Management NIMSOFT PROBES

Issue/Introduction

How to monitor Custom (Ex: Dell) Windows Event Logs

<Please see attached file for image>

User-added image

On a Windows 2012 server, we deployed ntevl probe to monitor Windows event logs. The Source of events we need to monitor is "ServerHardwareManager" which falls under "Applications and Services Log" under "Dell".
However, the required Log File "Applications and Services Log" is not present in Available Log Files under "Setup" tab in "ntevl" probe.
How to monitor these Dell Hardware events through "ntevl" probe? as they are not visible in the Probe

<Please see attached file for image>

User-added image

Environment

UIM 8.51
ntevl probe 4.31 & above
Windows

Resolution

As this custom Event log doesn't show up in the "ntevl" available logs, run following commands on the Probe machine

1) wevtutil el
This will list all available Events logs as shown below

<Please see attached file for image>

User-added image

2) Check each event log from the above list, for Dell Hardware events, the log name is "Monitor" then run a command "wevtutil gl Monitor" to confirm the same as it will give details about the event log etc (see below picture)

<Please see attached file for image>

User-added image

From the above output, it is clear evident that this Dell log file name is "Monitor" (somewhere near the bottom of the list). Check the probe again and look for a logname called just "Monitor" That will be the log that relates to the Dell entry in event viewer.

<Please see attached file for image>

User-added image

Attachments

1558688386158000130090_sktwi1f5rjvs16fka.jpeg get_app
1558688384093000130090_sktwi1f5rjvs16fk9.jpeg get_app
1558688382272000130090_sktwi1f5rjvs16fk8.jpeg get_app
1558688380373000130090_sktwi1f5rjvs16fk7.jpeg get_app
1558688377324000130090_sktwi1f5rjvs16fk6.jpeg get_app