Hi Miran.
After consulting with the team, I confirmed that if the events you want to monitor come from Windows, these events are actually managed through the Windows eventchannel. However, this is not a direct process, since the events are in XML format. These events must be previously processed by the manager to convert them from XML to JSON, before continuing with the normal process.
I'm currently preparing a summary so you can mock and test the rule you want to implement. I'm assuming you're trying to monitor an RDP event on Windows, but it would be helpful if you could confirm this, as the approach may vary depending on the operating system. Also, if you could provide me with the rule you created, it would be a great help to check the rule, perform tests, and to include it in the summary I am preparing for you.
Regards!