So, I want to try using the Event Log Forwarder on my desktops to send Logon/Logoff events over to Kiwi.
In Event Log Forwarder, I created a new Subscription, Selected Security, Event types of Error, Warning, and Info for included events 4624, 4634, and 4672
My default syslog facility is Local7
On the Kiwi side, I made a new rule, with message text filter "logon" and action to display to 02.
I also made a rule with message text file "logged off" and action to send to display 03.
In Kiwi, if I setup the Test message for text logon or logged off , I get the event, but I don't seem to be getting it from my desktop logon.
Can anyone point me in the right direction?
thanx,