If ServerA & ServerB are machines with agents, define them as the InsertionIP. Use an OR statement to grab data from both.
For the latter part, I'm uncertain whether your text is going to end up as the EventInfo, ExtraneousInfo, etc. Force the event to occur, note the timestamp, then see how the manager parses it by using nDepth to browse the events obtained from your InsertionIP during that time period.
if using a syslog server w/ agent rather than the systems sending directly, you'll use "detectionIP" for source. filter by those and see what information you get from there to drag and drop "fields" highlighted..."InferenceRule" or "EventInfo"
Event Info doesn't appear to be avail (or I'm missing it), but if you start with the IP(s) and filter, then you can determine the rest.
if too much info just by IP, then sort filter (refine fields) by clicking on 321 and that will order by number of events, drag that event over and click the "=" which makes it "not =". keep adding until you find what you need.