This rule looks for and collects M365 to Exchange events in the Operations Manager log.
This rule looks for and collects M365 to Exchange events in the Operations Manager log.
Target | Microsoft.SystemCenter.M365.WatcherNodeApplication |
Category | EventCollection |
Enabled | True |
Alert Generate | False |
Remotable | True |
ID | Module Type | TypeId | RunAs |
---|---|---|---|
Microsoft.Windows.EventCollector | DataSource | Microsoft.Windows.EventCollector | Default |
Microsoft.SystemCenter.CollectEvent | WriteAction | Microsoft.SystemCenter.CollectEvent | Default |
<Rule ID="Microsoft.SystemCenter.M365.Rules.M365ToExchange.EventCollectionRule" Enabled="true" Target="Microsoft.SystemCenter.M365.WatcherNodeApplication" ConfirmDelivery="false" Remotable="true" Priority="Normal" DiscardLevel="100">
<Category>EventCollection</Category>
<DataSources>
<DataSource ID="Microsoft.Windows.EventCollector" TypeID="Windows!Microsoft.Windows.EventCollector">
<ComputerName>$Target/Host/Property[Type="Windows!Microsoft.Windows.Computer"]/NetworkName$</ComputerName>
<LogName>Operations Manager</LogName>
<AllowProxying>false</AllowProxying>
<Expression>
<SimpleExpression>
<ValueExpression>
<XPathQuery Type="UnsignedInteger">EventDisplayNumber</XPathQuery>
</ValueExpression>
<Operator>Equal</Operator>
<ValueExpression>
<Value Type="UnsignedInteger">951</Value>
</ValueExpression>
</SimpleExpression>
</Expression>
</DataSource>
</DataSources>
<WriteActions>
<WriteAction ID="Microsoft.SystemCenter.CollectEvent" TypeID="SC!Microsoft.SystemCenter.CollectEvent"/>
</WriteActions>
</Rule>