So it turns out that the event log monitor will by nature report duplicate counts because it always goes back one additional polling cycle or more. So if it finds a new one now, the next cycle it will find that one again. This leads to inaccurate reporting to the number of times an event was logged for a given windows server.
I would like the ability to say "check over the past x minutes and no more" so that every X minutes it just finds if there were new events since the last check. Then I could report back "Server Y had X events with ID 1234 and "somephrase" and "somesource" in it.
Marked for PM to review.