This is not exactly ‘new’ technology but someone might find it useful. In recent Windows versions Microsoft enhanced the way the Event log work and function plus the way you can access it. The default Event Viewer inside Windows support creating ‘Views’ with which you can filter events based on your needs. If you know your XML syntax you can create some nice views for yourself. I created one for filtering all BizTalk related events that can simply be imported and then used as is. The XML looks like this:
<ViewerConfig> <QueryConfig> <QueryParams> <UserQuery /> </QueryParams> <QueryNode> <Name>BizTalk Server</Name> <QueryList> <Query Id="0" Path="Application"> <Select Path="Application">*[System[Provider[@Name='BizTalk Server']]]</Select> <Select Path="Application">*[System[Provider[@Name='BizTalk Server Deployment']]]</Select> <Select Path="Application">*[System[Provider[@Name='ENTSSO']]]</Select> </Query> </QueryList> </QueryNode> </QueryConfig> <ResultsConfig> <Columns> <Column Name="Level" Type="System.String" Path="Event/System/Level" Visible="">120</Column> <Column Name="Keywords" Type="System.String" Path="Event/System/Keywords">70</Column> <Column Name="Date and Time" Type="System.DateTime" Path="Event/System/TimeCreated/@SystemTime" Visible="">170</Column> <Column Name="Source" Type="System.String" Path="Event/System/Provider/@Name" Visible="">99</Column> <Column Name="Event ID" Type="System.UInt32" Path="Event/System/EventID" Visible="">80</Column> <Column Name="Task Category" Type="System.String" Path="Event/System/Task" Visible="">80</Column> <Column Name="User" Type="System.String" Path="Event/System/Security/@UserID">50</Column> <Column Name="Operational Code" Type="System.String" Path="Event/System/Opcode">110</Column> <Column Name="Log" Type="System.String" Path="Event/System/Channel">80</Column> <Column Name="Computer" Type="System.String" Path="Event/System/Computer">170</Column> <Column Name="Process ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessID">70</Column> <Column Name="Thread ID" Type="System.UInt32" Path="Event/System/Execution/@ThreadID">70</Column> <Column Name="Processor ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessorID">90</Column> <Column Name="Session ID" Type="System.UInt32" Path="Event/System/Execution/@SessionID">70</Column> <Column Name="Kernel Time" Type="System.UInt32" Path="Event/System/Execution/@KernelTime">80</Column> <Column Name="User Time" Type="System.UInt32" Path="Event/System/Execution/@UserTime">70</Column> <Column Name="Processor Time" Type="System.UInt32" Path="Event/System/Execution/@ProcessorTime">100</Column> <Column Name="Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@ActivityID">85</Column> <Column Name="Relative Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@RelatedActivityID">140</Column> <Column Name="Event Source Name" Type="System.String" Path="Event/System/Provider/@EventSourceName">140</Column> </Columns> </ResultsConfig> </ViewerConfig>
To use simply copy/past into an XML file and use the ‘Import Custom View…’ context menu option in the standard Event Log Viewer of Windows.
Of course, if you want a proper Event View solution over a whole group of servers use my Event Scavenger tool 😉