To filter the Windows Event Log based on a given keyword...
<QueryList>
<Query Id="0" Path="System">
<Select Path="System">*[System[Provider[@Name='Microsoft-Windows-Power-Troubleshooter']
and (EventID=1)]] and *[EventData[Data[15]='USB Root Hub']]</Select>
</Query>
</QueryList>
to adapt this query only change the data id (can be seen out of the detailed xml view of the eventlog entry
| Next > |
|---|




