ntevl probe triggered old event alerts during initial deployment.
The engineering team has provided a test build that resolved the issue in ntevl v4.34.
The test fix ntevl-4.34-T1-20221215.065758-5 has been attached to this knowledge article.
In a DX UIM 23.4 environment running ntevl v4.35, this same issue was observed and downgrading to 4.34-T1 resolved the issue.
WIth ntevl 4.35 the customer added an Event ID to a few of their servers. After restarting the ntevl probe, it sent new alarms for a previously configured Event ID for an old event that occurred the day before. It appeared to be reading the entire Windows event log again from the beginning and sending new alerts.
This test fix also resolved the issue with old events being generated when using ntevl 4.35.