I installed the ACS collector in Win2008SP1. I find that the eventID is not
mapping right for the category.
EG:
EvevntID 4662 its category should be DS Access,but in the database its
category is Privilege Use. And there are also a lots Win2008 and vista
eventid's category is n/a in the database.
I also open the debug model for the ACS find the log below:
[20090908 233713,164][Debug ]AdtsEvent::MapStrings(): AdtsEvent:
[20090908 233713,164][Debug ] EventId: 4662, SeqNo: 104341, Type: 8,
Category: 4
When I was testing ACS with 2008 AD I had to re-write the ACS reports. I
have a blog post about how to do that at http://contoso.se/blog/?p=288
--
Anders Bengtsson
Microsoft MVP - Operations Manager
www.contoso.se