Thank you for your quick response. We have installed the latest nightly build version and conducted some tests with the trace function enabled.
I hope we used the correct command syntax. Please find the attached trace, which includes the version used, the result, and the corresponding Windows event.
Unfortunately, we are still receiving the message “OK - Event log seems fine” when using both commands, “id=8198” and “filter=provider = 'Microsoft-Windows-Security-SPP’”.
SNClient+ v0.27.0030 (Build: d7f2f28, go1.22.8) |'version'=0.27003
[2024-10-11 10:44:05.791][Trace][pid:1972][listener:317] incoming nrpe connection from
192.168.107.60:50932[2024-10-11 10:44:05.811][Trace][pid:1972][listen_nrpe:106] nrpe v2 request: check_eventlog []string{" filter=provider = 'Microsoft-Windows-Security-SPP' id = 8198"}
[2024-10-11 10:44:05.811][Trace][pid:1972][snclient:694] command: check_eventlog
[2024-10-11 10:44:05.811][Trace][pid:1972][snclient:695] args: []string{" filter=provider = 'Microsoft-Windows-Security-SPP' id = 8198"}
[2024-10-11 10:44:05.811][Debug][pid:1972][listener:337] nrpe connection from
192.168.107.60:50932 finished in 19.6614ms
[2024-10-11 10:44:13.407][Trace][pid:1972][listener:317] incoming nrpe connection from
192.168.107.60:33194[2024-10-11 10:44:13.437][Trace][pid:1972][listen_nrpe:106] nrpe v2 request: check_eventlog []string{" filter=provider = 'Microsoft-Windows-Security-SPP' and id = 8198"}
[2024-10-11 10:44:13.437][Trace][pid:1972][snclient:694] command: check_eventlog
[2024-10-11 10:44:13.437][Trace][pid:1972][snclient:695] args: []string{" filter=provider = 'Microsoft-Windows-Security-SPP' and id = 8198"}
[2024-10-11 10:44:13.474][Trace][pid:1972][check_eventlog_windows:51] fetching eventlog: Application
...
[2024-10-11 10:44:13.873][Trace][pid:1972][check_eventlog_windows:86] expanded unique filter: Application-Microsoft-Windows-Security-SPP-16384
[2024-10-11 10:44:13.873][Trace][pid:1972][check_eventlog_windows:86] expanded unique filter: Application-Microsoft-Windows-Security-SPP-8198[2024-10-11 10:44:13.873][Trace][pid:1972][check_eventlog_windows:86] expanded unique filter: Application-Microsoft-Windows-Security-SPP-1003
....
[2024-10-11 10:44:17.588][Trace][pid:1972][checkdata:120] finalize check results:
[2024-10-11 10:44:17.588][Debug][pid:1972][checkdata:128] filter: provider = 'Microsoft-Windows-Security-SPP' and id = 8198
[2024-10-11 10:44:17.588][Debug][pid:1972][checkdata:129] condition warning: level = 'warning' or problem_count > 0
[2024-10-11 10:44:17.588][Debug][pid:1972][checkdata:130] condition critical: level in ('error', 'critical')
[2024-10-11 10:44:17.588][Debug][pid:1972][checkdata:131] condition ok: none
[2024-10-11 10:44:17.588][Trace][pid:1972][checkdata:133] details: map[string]string{"_state":"0", "detail-syntax":"%(file) %(source) (%(message))", "empty-syntax":"%(status) - No entries found", "ok-syntax":"%(status) - Event log seems fine", "top-syntax":"%(status) - %(count) message(s) %(problem_list)"}
[2024-10-11 10:44:17.588][Trace][pid:1972][checkdata:151] list data:
[2024-10-11 10:44:17.588][Trace][pid:1972][checkdata:174] - map[string]string{"_count":"5", "_state":"0", "computer":"VMSRV19-TESTVD.BSI.local", "file":"Application", "id":"8198", "level":"fehler", "log":"Application", "message":"Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:\r\nhr=0x87E10BC6\r\nBefehlszeilenargumente:\r\nRuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=175a4401-9571-44e3-b7ed-1418ac983e2b;NotificationInterval=1440;Trigger=UserLogon;SessionId=4", "provider":"Microsoft-Windows-Security-SPP", "source":"Microsoft-Windows-Security-SPP", "written":"2024-10-11 09:05:13 CEST", "writtenTS":"1728630313"}
[2024-10-11 10:44:17.588][Trace][pid:1972][checkdata:179] detail template: %(file) %(source) (%(message))
[2024-10-11 10:44:17.588][Trace][pid:1972][checkdata:213] output template: %(status) - Event log seems fine
[2024-10-11 10:44:17.588][Debug][pid:1972][listener:337] nrpe connection from
192.168.107.60:33194 finished in 4.1808928s
Protokollname: Application
Quelle: Microsoft-Windows-Security-SPP
Datum: 11.10.2024 09:05:13
Benutzer: Nicht zutreffend
Computer: VMSRV19-TESTVD.BSI.local
Beschreibung:
Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0x87E10BC6
Befehlszeilenargumente:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=175a4401-9571-44e3-b7ed-1418ac983e2b;NotificationInterval=1440;Trigger=UserLogon;SessionId=4
Ereignis-XML:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
<EventID Qualifiers="49152">8198</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2024-10-11T07:05:13.092429300Z" />
<EventRecordID>20714</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>VMSRV19-TESTVD.BSI.local</Computer>
<Security />
</System>
<EventData>
<Data>hr=0x87E10BC6</Data>
<Data>RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=175a4401-9571-44e3-b7ed-1418ac983e2b;NotificationInterval=1440;Trigger=UserLogon;SessionId=4</Data>
</EventData>
</Event>