Hi,
I'd like to setup alerts that email us when Windows Defender takes an action. Actions and event ID's are listed here:
The issue is I'm unable to select the Event Log Source as the Windows Defender log. The only options are Application, System, and Security, and Defender keeps its logs in its own log under "Applications and Services Logs". In order to monitor that log it has to be selected as the source.
How can I instruct Remote Monitoring to watch for the events in: Microsoft-Windows-Windows Defender/Operational
With event ID's: 1005,1006,1007,1008,1015,1116,1117,1118,1119
?