New
#370
The xml file Custom view definitions in my last post are:-
WU<ViewerConfig>
<QueryConfig>
<QueryParams>
<UserQuery/>
</QueryParams>
<QueryNode>
<Name LanguageNeutralValue="WU">WU</Name>
<Description>FullWU, WinDefr updates, App updates - shows failures</Description>
<SortConfig Asc="0">
<Column Name="Date and Time" Type="System.DateTime" Path="Event/System/TimeCreated/@SystemTime" Visible="">115</Column>
</SortConfig>
<QueryList>
<Query Id="0" Path="Microsoft-Windows-Windows Defender/Operational">
<Select Path="Microsoft-Windows-Windows Defender/Operational">*[System[(EventID=2000 or EventID=2001)]]</Select>
<Select Path="Microsoft-Windows-WindowsUpdateClient/Operational">*[System[(EventID=41 or EventID=31 or EventID=26)]]</Select>
</Query>
</QueryList>
</QueryNode>
</QueryConfig>
<ResultsConfig>
<Columns>
<Column Name="Level" Type="System.String" Path="Event/System/Level" Visible="">87</Column>
<Column Name="Date and Time" Type="System.DateTime" Path="Event/System/TimeCreated/@SystemTime" Visible="">115</Column>
<Column Name="Log" Type="System.String" Path="Event/System/Channel" Visible="">307</Column>
<Column Name="Source" Type="System.String" Path="Event/System/Provider/@Name" Visible="">144</Column>
<Column Name="Event ID" Type="System.UInt32" Path="Event/System/EventID" Visible="">144</Column>
<Column Name="Task Category" Type="System.String" Path="Event/System/Task" Visible="">144</Column>
<Column Name="Keywords" Type="System.String" Path="Event/System/Keywords">70</Column>
<Column Name="User" Type="System.String" Path="Event/System/Security/@UserID">50</Column>
<Column Name="Operational Code" Type="System.String" Path="Event/System/Opcode">110</Column>
<Column Name="Computer" Type="System.String" Path="Event/System/Computer">170</Column>
<Column Name="Process ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessID">70</Column>
<Column Name="Thread ID" Type="System.UInt32" Path="Event/System/Execution/@ThreadID">70</Column>
<Column Name="Processor ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessorID">90</Column>
<Column Name="Session ID" Type="System.UInt32" Path="Event/System/Execution/@SessionID">70</Column>
<Column Name="Kernel Time" Type="System.UInt32" Path="Event/System/Execution/@KernelTime">80</Column>
<Column Name="User Time" Type="System.UInt32" Path="Event/System/Execution/@UserTime">70</Column>
<Column Name="Processor Time" Type="System.UInt32" Path="Event/System/Execution/@ProcessorTime">100</Column>
<Column Name="Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@ActivityID">85</Column>
<Column Name="Relative Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@RelatedActivityID">140</Column>
<Column Name="Event Source Name" Type="System.String" Path="Event/System/Provider/@EventSourceName">140</Column>
</Columns>
</ResultsConfig>
</ViewerConfig>
WU - System log incl Apps<ViewerConfig><QueryConfig>
<QueryParams>
<Simple>
<Channel>System</Channel>
<EventId>19</EventId>
<Source>Microsoft-Windows-WindowsUpdateClient</Source>
<RelativeTimeInfo>0</RelativeTimeInfo>
<BySource>False</BySource>
</Simple>
</QueryParams>
<QueryNode>
<Name LanguageNeutralValue="Windows updates - System log">WU - System log incl Apps</Name>
<Description>FullWU, WinDefr updates, App updates - Useful for extracting update lists, does not show failures</Description>
<QueryList>
<Query Id="0" Path="System">
<Select Path="System">*[System[Provider[@Name='Microsoft-Windows-WindowsUpdateClient'] and (EventID=19)]]</Select>
</Query>
</QueryList>
</QueryNode>
</QueryConfig>
<ResultsConfig>
<Columns>
<Column Name="Level" Type="System.String" Path="Event/System/Level" Visible="">87</Column>
<Column Name="Date and Time" Type="System.DateTime" Path="Event/System/TimeCreated/@SystemTime" Visible="">115</Column>
<Column Name="Log" Type="System.String" Path="Event/System/Channel" Visible="">80</Column>
<Column Name="Source" Type="System.String" Path="Event/System/Provider/@Name" Visible="">144</Column>
<Column Name="Event ID" Type="System.UInt32" Path="Event/System/EventID" Visible="">144</Column>
<Column Name="Task Category" Type="System.String" Path="Event/System/Task" Visible="">144</Column>
<Column Name="Keywords" Type="System.String" Path="Event/System/Keywords">70</Column>
<Column Name="User" Type="System.String" Path="Event/System/Security/@UserID">50</Column>
<Column Name="Operational Code" Type="System.String" Path="Event/System/Opcode">110</Column>
<Column Name="Computer" Type="System.String" Path="Event/System/Computer">170</Column>
<Column Name="Process ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessID">70</Column>
<Column Name="Thread ID" Type="System.UInt32" Path="Event/System/Execution/@ThreadID">70</Column>
<Column Name="Processor ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessorID">90</Column>
<Column Name="Session ID" Type="System.UInt32" Path="Event/System/Execution/@SessionID">70</Column>
<Column Name="Kernel Time" Type="System.UInt32" Path="Event/System/Execution/@KernelTime">80</Column>
<Column Name="User Time" Type="System.UInt32" Path="Event/System/Execution/@UserTime">70</Column>
<Column Name="Processor Time" Type="System.UInt32" Path="Event/System/Execution/@ProcessorTime">100</Column>
<Column Name="Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@ActivityID">85</Column>
<Column Name="Relative Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@RelatedActivityID">140</Column>
<Column Name="Event Source Name" Type="System.String" Path="Event/System/Provider/@EventSourceName">140</Column>
</Columns>
</ResultsConfig>
</ViewerConfig>
WU - Setup log<ViewerConfig>
<QueryConfig>
<QueryParams>
<Simple>
<Channel>Setup</Channel>
<RelativeTimeInfo>0</RelativeTimeInfo>
</Simple>
</QueryParams>
<QueryNode>
<Name LanguageNeutralValue="Windows updates - Setup log">WU - Setup log</Name>
<Description>I used to capture wusa event 2 only and do not understand all the other sources and events yet</Description>
<SortConfig Asc="0">
<Column Name="Date and Time" Type="System.DateTime" Path="Event/System/TimeCreated/@SystemTime" Visible="">115</Column>
</SortConfig>
<QueryList>
<Query Id="0" Path="Setup">
<Select Path="Setup">*</Select>
</Query>
</QueryList>
</QueryNode>
</QueryConfig>
<ResultsConfig>
<Columns>
<Column Name="Level" Type="System.String" Path="Event/System/Level" Visible="">87</Column>
<Column Name="Date and Time" Type="System.DateTime" Path="Event/System/TimeCreated/@SystemTime" Visible="">115</Column>
<Column Name="Log" Type="System.String" Path="Event/System/Channel" Visible="">80</Column>
<Column Name="Source" Type="System.String" Path="Event/System/Provider/@Name" Visible="">225</Column>
<Column Name="Event ID" Type="System.UInt32" Path="Event/System/EventID" Visible="">225</Column>
<Column Name="Task Category" Type="System.String" Path="Event/System/Task" Visible="">229</Column>
<Column Name="Keywords" Type="System.String" Path="Event/System/Keywords">70</Column>
<Column Name="User" Type="System.String" Path="Event/System/Security/@UserID">50</Column>
<Column Name="Operational Code" Type="System.String" Path="Event/System/Opcode">110</Column>
<Column Name="Computer" Type="System.String" Path="Event/System/Computer">170</Column>
<Column Name="Process ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessID">70</Column>
<Column Name="Thread ID" Type="System.UInt32" Path="Event/System/Execution/@ThreadID">70</Column>
<Column Name="Processor ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessorID">90</Column>
<Column Name="Session ID" Type="System.UInt32" Path="Event/System/Execution/@SessionID">70</Column>
<Column Name="Kernel Time" Type="System.UInt32" Path="Event/System/Execution/@KernelTime">80</Column>
<Column Name="User Time" Type="System.UInt32" Path="Event/System/Execution/@UserTime">70</Column>
<Column Name="Processor Time" Type="System.UInt32" Path="Event/System/Execution/@ProcessorTime">100</Column>
<Column Name="Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@ActivityID">85</Column>
<Column Name="Relative Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@RelatedActivityID">140</Column>
<Column Name="Event Source Name" Type="System.String" Path="Event/System/Provider/@EventSourceName">140</Column>
</Columns>
</ResultsConfig>
</ViewerConfig>
Denis