Hello.
I have another monitoring issue and I need to monitor windows events, I know how to configure to monitor it from the event console, but is it possible to monitor only one event per ID without having to enable the syslog in checkmk or configure the “event rules”?
I have made several tests with the “Finetune Windows Eventlog monitoring” rule and with the “logfile patterns” rule, I have modified the file “C:\ProgramData\checkmk\agent\check_mk.user.yml” and in no case I have been able to get something clear.