I have done this before. I got everything set up and working then another employee took over the task. They then moved and took the computer with them. That employee recently moved to another position and UPS "lost" the computer, so I am now trying to get it set up on a new machine. I do remember when configuring the previous box I used WinEventLog somewhere in the process. I thought it was in the Source Type under operating system but all I see there now is windows_snare_syslog and that does not seem to work either.
... View more