So, I have been struggling with creating a monitor. What I am looking at doing is monitoring the "Microsoft-Windows-Backup/Operational" log on server 2008R2. I have a scheduled tack that runs on my domain controller that performs System State Back Ups (SSBU). WBAdmin.exe writes its events to this log. I want to scan the log for any failured "Event IDs 5,19,or 20" and if present show the status as down or critical. Everything I have tried either fails with No Event(s) matched, eventhought I know there are EventIDs 19 & 20 present in the log. Any pointers on correctly setting up this monitor will be greatly appreciated.
Thanks in advance
Smitty