Recently downloaded the Log Forwarder for Windows agent.
Just need to know if any of the fields will support wild cards or regex when creating an event log subscription.
For example, when defining the 'Users(s)' field, you need to specify the "computername\username" when matching for local username activity.
Specifying just the 'username' will result in no matches.
I'm trying to package this up to deploy to hundreds of servers, but wanted to keep it simple as possible.
Thanks,
- v