Microsoft_Vista_and_Win_2008_Svr_v4.4.11 collector parse the events incorrectly
Created: 21 Feb 2013 | Updated: 21 Feb 2013 | 5 comments
I installed the ssim agent 4.7.1 and Microsoft_Vista_and_Win_2008_Svr_v4.4.11 collector to Win2008 R2 Domain Controller.
Somehow.... I configured collector to pull events from DC to SSIM.
But when i ran the qwery via ssim console i saw that all events have the same "severity-ID" and wrong "category" parsing. I mean, that the all of "system" and "application" windows events have the same category - "Application", although in the "vendor id" field is real value of this events.
Windows event that i identified on the picture must have "severity-id" higher then "1-information" (it must have "5" or "4" type)
Is there some KB for this issue? What the latest release-number of the Microsoft_Vista_and_Win_2008_Svr_v4.4.11 collector?
p/s: From the Microsoft_Vista_and_Win_2008_Svr_v4.4.11 "collector.propertis" file:
#Fri Feb 27 08:49:44 PST 2009