Logwatch liefert keine Daten von Application & Services

Hallo, ich möchte mittels logwatch Daten von Application & Services Logs einsammeln, z.B.
Microsoft-Windows-FailoverClustering/Operational

Trotz mehrerer Versuche gelingt mir das jedoch nicht.

check_mk_agent showconfig liefert folgendes:

logwatch:
  enabled: true
  sendall: false
  vista_api: no
  skip_duplicated: false
  max_size: 500000
  max_line_length: -1
  max_entries: -1
  timeout: -1
  logfile:
    - microsoft-windows-failoverclustering/operational: all context
    - Parameters: ignore
    - State: ignore
    - "*": warn nocontext

check_mk_agent test output:
image
CheckmkService running/auto Checkmk Service
<<>>
[[[Application]]]
C Dec 30 09:07:31 49152.18456 MSSQLSERVER Login failed …
W Dec 30 09:52:30 32768.1202 SceCli Security policies were …
[[[HardwareEvents]]]
[[[Internet Explorer:missing]]]
[[[Key Management Service]]]
[[[Security:missing]]]
[[[System]]]
C Dec 30 09:05:12 0.36882 Schannel The certificate received …
[[[Veeam Agent]]]
[[[Windows PowerShell]]]
<<<>>>
<<<>>>

Was mache ich falsch?

Vielen Dank.