We have to search for EventCode 4656 for Windows 7 and 2008 Server.
A lot of the 4656 are caused by logons (4624) and is there a way to search for 4656 and only show ones that are not caused by a logon.
Lets say, dont show any 4656 within 30 seconds of a 4624.
Thanks
You might be able to filter your result set by looking at the "Process Name:" field. Or post a few of your offending events to get a better look as to what you need to filter out .