Source Nameseventtype="wineventlog_common" source="*inEventLog:$LogName$" (host="$EventHost$" OR ComputerName="$EventHost$") TaskCategory="$TaskCategory$" SourceName="$SourceName$" EventCode="$EventCode$" Type="$Type$" "$event.additional$" | stats sparkline as "Trend", count by SourceName | sort -count$time.earliest$$time.latest$
Task Categorieseventtype="wineventlog_common" source="*inEventLog:$LogName$" (host="$EventHost$" OR ComputerName="$EventHost$") TaskCategory="$TaskCategory$" SourceName="$SourceName$" EventCode="$EventCode$" Type="$Type$" $event.additional$ | stats sparkline as "Trend", count by TaskCategory | sort -count$time.earliest$$time.latest$
Hostseventtype="wineventlog_common" source="*inEventLog:$LogName$" (host="$EventHost$" OR ComputerName="$EventHost$") TaskCategory="$TaskCategory$" SourceName="$SourceName$" EventCode="$EventCode$" Type="$Type$" $event.additional$ | stats sparkline as "Trend", count by host | sort -count$time.earliest$$time.latest$
Event IDseventtype="wineventlog_common" source="*inEventLog:$LogName$" (host="$EventHost$" OR ComputerName="$EventHost$") TaskCategory="$TaskCategory$" SourceName="$SourceName$" EventCode="$EventCode$" Type="$Type$" $event.additional$ | eval EventCodeDescription=if(isnull(EventCodeDescription), mvindex(split(Message, "."), 0), EventCodeDescription) | stats sparkline as "Trend", count by EventCode, EventCodeDescription | sort -count$time.earliest$$time.latest$
Event Count By Hosts - Over Timeeventtype="wineventlog_common" source="*inEventLog:$LogName$" (host="$EventHost$" OR ComputerName="$EventHost$") TaskCategory="$TaskCategory$" SourceName="$SourceName$" EventCode="$EventCode$" Type="$Type$" $event.additional$ | timechart span=1m count by host$time.earliest$$time.latest$Event Count By Event Code - Over Timeeventtype="wineventlog_common" source="*inEventLog:$LogName$" (host="$EventHost$" OR ComputerName="$EventHost$") TaskCategory="$TaskCategory$" SourceName="$SourceName$" EventCode="$EventCode$" Type="$Type$" $event.additional$ | timechart span=1m count by EventCode$time.earliest$$time.latest$Event Counts By Log Name - Over Timeeventtype="wineventlog_common" source="*inEventLog:$LogName$" (host="$EventHost$" OR ComputerName="$EventHost$") TaskCategory="$TaskCategory$" SourceName="$SourceName$" EventCode="$EventCode$" Type="$Type$" $event.additional$ | timechart span=1m count by LogName$time.earliest$$time.latest$Event Counts By Type - Over Timeeventtype="wineventlog_common" source="*inEventLog:$LogName$" (host="$EventHost$" OR ComputerName="$EventHost$") TaskCategory="$TaskCategory$" SourceName="$SourceName$" EventCode="$EventCode$" Type="$Type$" $event.additional$ | timechart span=1m count by Type$time.earliest$$time.latest$