Knowledge Base


It is important that filters using summary notifications are NOT configured to notify All Targets. When using summary notifications make sure that one and only one target is present in the filters Targets list of the General tab.

KB-ID 9
Category: Configuration
Applies to:

After making configuration changes on your management workstation you will need to use the Update Configuration feature of remote update to push the updated configuration to your remote machines. Rightclick the Computers container of the group you want to update and select Update Configuration. In the next dialog make sure that the co...

KB-ID 10
Category: Configuration
Applies to: All Versions

You can export and thus backup the EventSentry configuration by selecting Export from the Home menu of the EventSentry management application. This will save the entire configuration from the registry in a .reg file. Alternatively you can also open up the registry editor e.g. regedit.exe and export the HKEYLOCALMACHINE\SOFTWARE\Wow6...

KB-ID 13
Category: Configuration
Applies to: All Versions

Yes any user with administrative privileges can view and change the EventSentry configuration. The entire EventSentry configuration is stored on a permachine basis so it doesn39t matter which user logs on to the computer where the EventSentry management application is installed. The only settings that are store on a peruser basis are th...

KB-ID 14
Category: Configuration
Applies to:

Filters are processed sequentially onebyone by the EventSentry agent. If an event matches multiple filters then every filter matching the event will send the event information to the configured target. This usually happens when more than one filter is configured to use All Targets. To avoid seeing events multiple times: Configure ...

KB-ID 16
Category: Configuration
Applies to: up to 2.60

In order to transfer the EventSentry configuration from a remote computer to the computer running the management application do the following: 1 Log in on one of the remote computers running the agent 2 Open up the registry editor regedit.exe and select the HKEYLOCALMACHINE\Software\netikus.net\EventSentry subkey 3 From the File or ...

KB-ID 55
Category: Configuration
Applies to:

Access to the EventSentry configuration is automatically restricted to members of the local Administrators group or Domain Admins group on domain controllers. Members of the Users and/or Domain Users groups do not have permission to view or edit the EventSentry configuration. The entire EventSentry configuration is stored in the registry an...

KB-ID 66
Category: Configuration
Applies to:

Yes you can make changes directly to the registry but always make a configuration backup before you make any changes to the registry. Please also note that editing the registry directly is not supported. To make sure that the EventSentry agent picks up the configuration changes you made create the following empty file when you are done edi...

KB-ID 103
Category: Configuration
Applies to: 2.72

You can monitor this event log through the Custom Event Log monitoring feature of EventSentry. Simply click the Custom Event Logs tab on an existing or new filter select the DFS Replication from the list and check the check box next to it. The selected event log will now also be monitored by this filter. To monitor this event log in other...

KB-ID 116
Category: Configuration
Applies to:

When packages that are assigned to individual computers do not work then please make sure that the computers in question are part of an AD domain. If the computers are not and/or cannot be part of an AD domain then you will have to manage the computers using their NetBIOS names. Otherwise EventSentry will not correctly identify the compute...

KB-ID 154
Category: Configuration
Applies to:

This error is being displayed because remote access connections which are available for selection on the SMTP action dialog cannot be enumerated. You should be able To avoid this error message by ensuring that the Remote Access Connection Manager service is running.

KB-ID 167
Category: Configuration
Applies to: 2.90

Events logged with a severity of Success which is displayed like an informational event are not very common but are nevertheless logged by some applications like SQL Server. EventSentry treats Success events like Information events as such you would need to filter for Information events when you want to process Success events.

KB-ID 170
Category: Configuration
Applies to:

EventSentry ships with a variety of default packages all of which are optimized for systems installed in English. Efforts are underway to support other languages as well for builtin performance counters however for the time a performance counter package for German systems has been made available. The package .reg file can be downloaded from...

KB-ID 236
Category: Configuration
Applies to: 2.93.1

Yes using the Regular Expression match type of an EventSentry event log filter you can get notified when a credit card number appears in an event log message or log file. Credit Card numbers should never be stored in clear text in any type of log file whether in a production or test environment. If you monitor your event logs and/or log fil...

KB-ID 242
Category: Configuration
Applies to: All Versions

Yes it is possible to monitor both of these directories on a 64bit machine with the Disable folder redirection on 64bit systems Wow64 option in File Monitoring. If you run the EventSentry agent on a 64bit machine and monitor folders for which the OS has file redirection for 32bit processes enabled e.g. SYSTEMROOT\SYSTEM32 then ...

KB-ID 243
Category: Configuration
Applies to: 2.93 or newer

Yes. To set up access to modify groups packages and other configuration changes: Create an Active Directory security group which we will call ESAdmins in this example and then add the users that will be managing EventSentry to that group. Then configure the EventSentry registry key to have Full Access permissions granted to the ESA...

KB-ID 262
Category: Configuration
Applies to: 3.0

When EventSentry is installed there is an option in the Configuration Assistant to purge data older than the number of days specified. If you would like modify the number of days please follow the steps below. Open the EventSentry Management Console Click Tools Embedded Scripts Select autodbpurge.cmd Edit the number of ...

KB-ID 289
Category: Configuration
Applies to: v3.1 or later

The quickest way to exclude unwanted service status change events such as the aelookupsvc is to added them to the list of excluded services: In the management console find the EventSentry Alerts package under Packages/Event Logs Expand the package and locate the Excluded Services exclusion filter under Service Monitoring. If you a...

KB-ID 300
Category: Configuration
Applies to: 3.0.1 and later

Please ensure that you do not have Registry Auditing enabled for the following registry path: HKEYLOCALMACHINE\SOFTWARE\netikus.net\EventSentry\bootscan HKEYLOCALMACHINE\SOFTWARE\Wow6432node\netikus.net\EventSentry\bootscan Usually registry auditing becomes enabled for this path due to auditing the EventSentry registry path or auditing ...

KB-ID 304
Category: Configuration
Applies to: All Versions

Yes to get notified when an IIS site is stopped or started follow the steps below: 1. In the Windows event viewer navigate to the MicrosoftWindowsIISConfigurationOperational event log 2. Rightclick the log and select Enable Log 3. In EventSentry create a new include filter which looks for the following event properties: ...

KB-ID 305
Category: Configuration
Applies to: All Versions

Yes it is possible to only send one event per email. In the EventSentry console scroll down the left side to the Actions section and then select one of your email actions. On the right side in the email action39s settings you can change the Events Per Email setting in the bottom right corner to 1 and repeat this change for all other em...

KB-ID 322
Category: Configuration
Applies to: 3.0.1 and later

Yes EventSentry includes a Remote Update eventsentryupd.exe command line utility that will allow you to automate the remote update process. You can schedule the update using the Windows Task Scheduler and assure that all of your agents are always running with the latest uptodate configuration. The utility also has an optional flag to updat...

KB-ID 323
Category: Configuration
Applies to: All Versions

The National Security Agency NSA and the Central Security Service CSS published the document Spotting the Adversary with Windows Event Log Monitoring which in section 4 lists a number of events which are recommended to be collected by a log / SIEM monitoring solution. We have made a downloadable EventSentry package file available for ...

KB-ID 338
Category: Configuration
Applies to: 3.3 and higher

Yes you can monitor several aspects of Subversion with EventSentry. We will assume that SVN is installed in C:\CSVN and that the repositories are installed in C:\SVN. Services CollabNet Subversion Edge csvnconsole CollabNet Subversion Server collabnetsubversionserver Disk Space Using folder monitoring System Health ...

KB-ID 341
Category: Configuration
Applies to: All Versions

Open the management console Navigate to Packages System Health In the ribbon click on the arrow below Filter and select Services Locate the appropriate package Services by default expand it and click on Services Add the service that should be excluded to the list. Save the configuration Excluding a service this way ...

KB-ID 356
Category: Configuration
Applies to: All Versions