Select Top 1000000 tsysOS.Image As icon,
  tblAssets.AssetID,
  tblAssets.AssetName,
  tblAssets.Domain,
  tblAssets.IPAddress,
  tsysOS.OSname,
  tblAssets.SP,
  tblNtlog.Eventcode,
  Case tblNtlog.Eventtype When 1 Then 'Error' When 2 Then 'Warning'
    When 3 Then 'Information' When 4 Then 'Success Audit'
    When 5 Then 'Failure Audit' End As Eventtype,
  tblNtlogFile.Logfile,
  tblNtlogMessage.Message,
  tblNtlogSource.Sourcename,
  tblNtlogUser.Loguser,
  tblNtlog.TimeGenerated
From tblAssets
  Inner Join tsysOS On tsysOS.OScode = tblAssets.OScode
  Inner Join tblNtlog On tblAssets.AssetID = tblNtlog.AssetID
  Inner Join tblNtlogFile On tblNtlogFile.LogfileID = tblNtlog.LogfileID
  Inner Join tblNtlogMessage On tblNtlogMessage.MessageID = tblNtlog.MessageID
  Inner Join tblNtlogSource On tblNtlogSource.SourcenameID =
    tblNtlog.SourcenameID
  Inner Join tblNtlogUser On tblNtlogUser.LoguserID = tblNtlog.LoguserID
Where tblNtlog.Eventcode = '64' And tblNtlogSource.Sourcename Like
  '%Microsoft-Windows-CertificateServicesClient-AutoEnrollment%' And
  tblNtlog.TimeGenerated > GetDate() - 7
Order By tblNtlog.TimeGenerated Desc
This is what I have from a previous post here on the forums. I changed the ID and source name but nothing is pulling. Am I running this report properly? Was hoping to pull event id 64 if found in the last 7 days on a server. Thanks in advance for the help.