could somebody help me with this? I need to create a query based on an user defined rule created where it has the report option enabled. How can I query the events generated with this rule?
KB Article KB52417 describes the Events VSE can send to ePO or log to the local event log.
You are looking for Event 1095, which is the Access Protection event for file/folder based rules being violated.
You would then create a query for that event, or filter an existing one to show only those events.