Hi, our server team is currently evaluating APM on top of our NPM installation. They're pretty taken with the system at the moment but want to be able to monitor windows event logs with the 'Windows Event Log Monitor' component and exclude events from being monitored based on their Event ID. (Current functionality only allows only inclusion based on Event ID).
I realise there is the event log forwarder tool that provides this functionality by prepending a minus sign to the event ID but they're not happy installing what amounts to client software for monitoring and having to do it through syslog.
Mods, if you're reading this and it isn't currently possible please consider this a formal feature request.