cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
steven_reid
Engaged Sweeper

Hi,

We are looking to implement WDAC and so would like to get a report on the following Event IDs in the event log.

  1. Applications and Services Logs - Microsoft - Windows - AppLocker -MSI and Script -- Filter with Event ID 8028
  2. Applications and Services Logs - Microsoft - Windows - CodeIntegrity -Operational --Filter with Event ID 3076

We only use the LSAgent to scan our computers as they are all EntraID Joined and spread out around the country.

Is it possible to scan for informational events via LSAgent?

I was looking to use a similar report to the DCOM Hardening report that I found in the Report Library.

Thanks in advance!

1 ACCEPTED SOLUTION
Obi_1_Cinobi
Lansweeper Tech Support
Lansweeper Tech Support

Hello there!

Unfortunately, this is currently not possible with LsAgent, but we would love to add your use case to our customer wish list. Please log a support case for this: https://www.lansweeper.com/contact/contact-support/

View solution in original post

2 REPLIES 2
Rodney
Engaged Sweeper

Hi. Is there any progress on this? We would also really like to have this option.

It would also be great if you could make these scan settings for typical Windows logs as well. At the moment, downloading all logs to the LS database and then searching them in reports is not the best solution.

We would also like to be able to scan selected Event IDs for specific machine groups as well as apply exclusions only to specific machine groups.

Obi_1_Cinobi
Lansweeper Tech Support
Lansweeper Tech Support

Hello there!

Unfortunately, this is currently not possible with LsAgent, but we would love to add your use case to our customer wish list. Please log a support case for this: https://www.lansweeper.com/contact/contact-support/