2 Replies Latest reply on Aug 25, 2016 12:42 AM by datasunrise492

    Stuck on adding a Advanced System Parser (ASP) to take over event parsing from windows Events Rules. (Using WMI)

    problematiq

           I have created two parsing rules to take over the function of the STATUS_SHUTDOWN_CLEAN Rule under Windows Events so that I can create correlation rules based on a shutdown or a reboot of a machine.

      The RegEx works fine, and the "Rule Assignment Type:" is set to "Windows Event Log - WMI" tags are Base: Windows and ASP:Microsoft. After much searching I have found nothing but dead ends. ANY help would be nice. As it is the "STATUS_SHUTDOWN_CLEAN" no longer parses the events and now neither do my new ASP Rules.