Just upgraded to SAM 5.2. Creating a new monitor template with a Windows Event Log Monitor component.
I have set it to monitor any log.
I set the match definition to Custom.
I leave the Log Source blank.
I set the event type to Error.
I set number of past polling intervalls to search for events to 1.
I set collect detailed data of events to True.
I set if a match is found in a polling period to Down
When I set Event ID to exclude specific IDS, if a enter a single ID, then it works by excluding that ID. But if I put multiple IDs separated by commas, it still includes all those IDs in the results.
Am I missing something? Or do I need to contact support?
Bryan