I need to check the Windows NT Event Log in some servers, but im not sure how that alet works because i added the alert id (e. 6008) under "Match String" and checked System Log as Critical, but when the event is generated on the client the alert is not triggered. Im not sure how should i have to fill the "Match String" field.
I need to generate an alert with the next event:
Product: Windows Operating System
Event ID: 6008
Component: System Event Log
Message: The previous system shutdown at %1 on %2 was unexpected.
Note: we haver other performance and services alerts and they work fine...
LDMS 88 SP3 (Server Manager, Security Suite)