We have configured ntevl event ID's 1069,1282 for windows failover clustering, we can see from failover events in windows server event log viewer, but the alarms are not getting triggered from CA UIM.
PFB the SC of Windows server event viewer:
Release: 20.3
Component: ntevl probe
Mostly valid for all ntevl versions
<Event-1069>
active = yes
description = Event log message with event ID 1069
level = major
logs = system
severity = 2
source = Microsoft-Windows-FailoverClustering
category = *
event_id = 1069
user = *
computer = *
message = *
send_alarm = yes
alarm_message = $source($event_id - $category): $message
i18n_token = as#system.ntevl.src_id_cat_1
send_subject = no
subject =
subsystem =
suppress = no
suppression_key =
send_to_axa =
tenant_id =
tags =
exclusive = no
qos_count = yes
qos_interval = 300
time_frame =
evt_count =
evt_count_condition =
runcommandonmatch = 0
commandexecutable =
commandarguments =
separator =
</Event-1069>
On probe level alarm was configured as major whereas this is an error message at the windows level, as both are mis-matching hence alarm did not sent. Post changing to 'error' it worked fine.