Newbie here. I was exploring Dashboard setup, so started doing some searches to create one with. I started eliminating Windows Events with the following:
source!="WinEventLog:Application" source!="WinEventLog:Security" source!="WinEventLog:Setup"
Next I clicked on the the WinEventLog:System event to exclude it from the search, but it displayed 0 events in the little popup, but there are tons of them. When I added it to the search bar like this... :
source!="WinEventLog:Application" source!="WinEventLog:Security" source!="WinEventLog:Setup" source!="WinEventLog:System"
... no events displayed, but I know there are other events which I am trying to narrow down to. Why does adding a fourth Source!= result in the display of no results at all? It happens no matter what order the WinEventLog types are entered. I've tried rearranging them, but get the same results. Obviously, this may not be the best way to narrow down to a specific event, but this approach has me wondering what is wrong.
... View more