{
"agent": {
"ip": "xxxxxxxxx",
"name": "agente1",
"id": "044"
},
"previous_output": "{\"win\":{\"system\":{\"providerName\":\"Application Error\",\"eventID\":\"1000\",\"level\":\"2\",\"task\":\"100\",\"keywords\":\"0x80000000000000\",\"systemTime\":\"2021-03-03T00:43:29.144146100Z\",\"eventRecordID\":\"27569\",\"channel\":\"Application\",\"computer\":\"agente1\",\"severityValue\":\"ERROR\",\"message\":\"\\\"Faulting application name: SolarWinds.Orion.LogMgmt.TrapService.exe, version: 2.2.0.14784, time stamp: 0x5da00feb\\r\\nFaulting module name: KERNELBASE.dll, version: 10.0.14393.1770, time stamp: 0x59bf2ba6\\r\\nException code: 0xe0434352\\r\\nFault offset: 0x0000000000033c58\\r\\nFaulting process id: 0x924\\r\\nFaulting application start time: 0x01d70fc62cd169e5\\r\\nFaulting application path: C:\\\\Program Files (x86)\\\\SolarWinds\\\\Orion\\\\OLM\\\\SolarWinds.Orion.LogMgmt.TrapService.exe\\r\\nFaulting module path: C:\\\\Windows\\\\System32\\\\KERNELBASE.dll\\r\\nReport Id: b7a0aaa4-3129-4d81-ad2e-609a3a69f117\\r\\nFaulting package full name: \\r\\nFaulting package-relative application ID: \\\"\"},\"eventdata\":{\"data\":\"SolarWinds.Orion.LogMgmt.TrapService.exe, 2.2.0.14784, 5da00feb, KERNELBASE.dll, 10.0.14393.1770, 59bf2ba6, e0434352, 0000000000033c58, 924, 01d70fc62cd169e5, C:\\\\\\\\Program Files (x86)\\\\\\\\SolarWinds\\\\\\\\Orion\\\\\\\\OLM\\\\\\\\SolarWinds.Orion.LogMgmt.TrapService.exe, C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll, b7a0aaa4-3129-4d81-ad2e-609a3a69f117\"}}}\n{\"win\":{\"system\":{\"providerName\":\"Application Error\",\"eventID\":\"1000\",\"level\":\"2\",\"task\":\"100\",\"keywords\":\"0x80000000000000\",\"systemTime\":\"2021-03-03T00:43:28.706626300Z\",\"eventRecordID\":\"27567\",\"channel\":\"Application\",\"computer\":\"agente1\",\"severityValue\":\"ERROR\",\"message\":\"\\\"Faulting application name: SolarWinds.Orion.LogMgmt.PollingService.exe, version: 2.2.0.14784, time stamp: 0xf87793b1\\r\\nFaulting module name: KERNELBASE.dll, version: 10.0.14393.1770, time stamp: 0x59bf2ba6\\r\\nException code: 0xe0434352\\r\\nFault offset: 0x0000000000033c58\\r\\nFaulting process id: 0x14e4\\r\\nFaulting application start time: 0x01d70fc62cd63669\\r\\nFaulting application path: C:\\\\Program Files (x86)\\\\SolarWinds\\\\Orion\\\\OLM\\\\SolarWinds.Orion.LogMgmt.PollingService.exe\\r\\nFaulting module path: C:\\\\Windows\\\\System32\\\\KERNELBASE.dll\\r\\nReport Id: 7e1e5b0b-1af0-451a-b0d7-3884a4463834\\r\\nFaulting package full name: \\r\\nFaulting package-relative application ID: \\\"\"},\"eventdata\":{\"data\":\"SolarWinds.Orion.LogMgmt.PollingService.exe, 2.2.0.14784, f87793b1, KERNELBASE.dll, 10.0.14393.1770, 59bf2ba6, e0434352, 0000000000033c58, 14e4, 01d70fc62cd63669, C:\\\\\\\\Program Files (x86)\\\\\\\\SolarWinds\\\\\\\\Orion\\\\\\\\OLM\\\\\\\\SolarWinds.Orion.LogMgmt.PollingService.exe, C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll, 7e1e5b0b-1af0-451a-b0d7-3884a4463834\"}}}\n{\"win\":{\"system\":{\"providerName\":\"Application Error\",\"eventID\":\"1000\",\"level\":\"2\",\"task\":\"100\",\"keywords\":\"0x80000000000000\",\"systemTime\":\"2021-03-03T00:43:24.831613400Z\",\"eventRecordID\":\"27564\",\"channel\":\"Application\",\"computer\":\"agente1\",\"severityValue\":\"ERROR\",\"message\":\"\\\"Faulting application name: SolarWinds.Orion.LogMgmt.SyslogService.exe, version: 2.2.0.14784, time stamp: 0x5da00ff2\\r\\nFaulting module name: KERNELBASE.dll, version: 10.0.14393.1770, time stamp: 0x59bf2ba6\\r\\nException code: 0xe0434352\\r\\nFault offset: 0x0000000000033c58\\r\\nFaulting process id: 0x109c\\r\\nFaulting application start time: 0x01d70fc62aaf6b14\\r\\nFaulting application path: C:\\\\Program Files (x86)\\\\SolarWinds\\\\Orion\\\\OLM\\\\SolarWinds.Orion.LogMgmt.SyslogService.exe\\r\\nFaulting module path: C:\\\\Windows\\\\System32\\\\KERNELBASE.dll\\r\\nReport Id: 98a90798-aea0-4e47-a7c8-8b86ae4cd445\\r\\nFaulting package full name: \\r\\nFaulting package-relative application ID: \\\"\"},\"eventdata\":{\"data\":\"SolarWinds.Orion.LogMgmt.SyslogService.exe, 2.2.0.14784, 5da00ff2, KERNELBASE.dll, 10.0.14393.1770, 59bf2ba6, e0434352, 0000000000033c58, 109c, 01d70fc62aaf6b14, C:\\\\\\\\Program Files (x86)\\\\\\\\SolarWinds\\\\\\\\Orion\\\\\\\\OLM\\\\\\\\SolarWinds.Orion.LogMgmt.SyslogService.exe, C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll, 98a90798-aea0-4e47-a7c8-8b86ae4cd445\"}}}\n{\"win\":{\"system\":{\"providerName\":\"Application Error\",\"eventID\":\"1000\",\"level\":\"2\",\"task\":\"100\",\"keywords\":\"0x80000000000000\",\"systemTime\":\"2021-03-03T00:42:04.955359800Z\",\"eventRecordID\":\"27560\",\"channel\":\"Application\",\"computer\":\"agente1\",\"severityValue\":\"ERROR\",\"message\":\"\\\"Faulting application name: SolarWinds.Orion.LogMgmt.PollingService.exe, version: 2.2.0.14784, time stamp: 0xf87793b1\\r\\nFaulting module name: KERNELBASE.dll, version: 10.0.14393.1770, time stamp: 0x59bf2ba6\\r\\nException code: 0xe0434352\\r\\nFault offset: 0x0000000000033c58\\r\\nFaulting process id: 0xb3c\\r\\nFaulting application start time: 0x01d70fc5faa40d88\\r\\nFaulting application path: C:\\\\Program Files (x86)\\\\SolarWinds\\\\Orion\\\\OLM\\\\SolarWinds.Orion.LogMgmt.PollingService.exe\\r\\nFaulting module path: C:\\\\Windows\\\\System32\\\\KERNELBASE.dll\\r\\nReport Id: 4b7cf482-f838-408e-9d46-cf74b425c752\\r\\nFaulting package full name: \\r\\nFaulting package-relative application ID: \\\"\"},\"eventdata\":{\"data\":\"SolarWinds.Orion.LogMgmt.PollingService.exe, 2.2.0.14784, f87793b1, KERNELBASE.dll, 10.0.14393.1770, 59bf2ba6, e0434352, 0000000000033c58, b3c, 01d70fc5faa40d88, C:\\\\\\\\Program Files (x86)\\\\\\\\SolarWinds\\\\\\\\Orion\\\\\\\\OLM\\\\\\\\SolarWinds.Orion.LogMgmt.PollingService.exe, C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll, 4b7cf482-f838-408e-9d46-cf74b425c752\"}}}\n{\"win\":{\"system\":{\"providerName\":\"Application Error\",\"eventID\":\"1000\",\"level\":\"2\",\"task\":\"100\",\"keywords\":\"0x80000000000000\",\"systemTime\":\"2021-03-03T00:42:04.861609300Z\",\"eventRecordID\":\"27559\",\"channel\":\"Application\",\"computer\":\"agente1\",\"severityValue\":\"ERROR\",\"message\":\"\\\"Faulting application name: SolarWinds.Orion.LogMgmt.TrapService.exe, version: 2.2.0.14784, time stamp: 0x5da00feb\\r\\nFaulting module name: KERNELBASE.dll, version: 10.0.14393.1770, time stamp: 0x59bf2ba6\\r\\nException code: 0xe0434352\\r\\nFault offset: 0x0000000000033c58\\r\\nFaulting process id: 0x1968\\r\\nFaulting application start time: 0x01d70fc5faa40bea\\r\\nFaulting application path: C:\\\\Program Files (x86)\\\\SolarWinds\\\\Orion\\\\OLM\\\\SolarWinds.Orion.LogMgmt.TrapService.exe\\r\\nFaulting module path: C:\\\\Windows\\\\System32\\\\KERNELBASE.dll\\r\\nReport Id: e41dd320-26cf-476e-9644-26427dae9293\\r\\nFaulting package full name: \\r\\nFaulting package-relative application ID: \\\"\"},\"eventdata\":{\"data\":\"SolarWinds.Orion.LogMgmt.TrapService.exe, 2.2.0.14784, 5da00feb, KERNELBASE.dll, 10.0.14393.1770, 59bf2ba6, e0434352, 0000000000033c58, 1968, 01d70fc5faa40bea, C:\\\\\\\\Program Files (x86)\\\\\\\\SolarWinds\\\\\\\\Orion\\\\\\\\OLM\\\\\\\\SolarWinds.Orion.LogMgmt.TrapService.exe, C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll, e41dd320-26cf-476e-9644-26427dae9293\"}}}\n{\"win\":{\"system\":{\"providerName\":\"Application Error\",\"eventID\":\"1000\",\"level\":\"2\",\"task\":\"100\",\"keywords\":\"0x80000000000000\",\"systemTime\":\"2021-03-03T00:42:01.874322700Z\",\"eventRecordID\":\"27555\",\"channel\":\"Application\",\"computer\":\"agente1\",\"severityValue\":\"ERROR\",\"message\":\"\\\"Faulting application name: SolarWinds.Orion.LogMgmt.SyslogService.exe, version: 2.2.0.14784, time stamp: 0x5da00ff2\\r\\nFaulting module name: KERNELBASE.dll, version: 10.0.14393.1770, time stamp: 0x59bf2ba6\\r\\nException code: 0xe0434352\\r\\nFault offset: 0x0000000000033c58\\r\\nFaulting process id: 0x1290\\r\\nFaulting application start time: 0x01d70fc5fa1c13e4\\r\\nFaulting application path: C:\\\\Program Files (x86)\\\\SolarWinds\\\\Orion\\\\OLM\\\\SolarWinds.Orion.LogMgmt.SyslogService.exe\\r\\nFaulting module path: C:\\\\Windows\\\\System32\\\\KERNELBASE.dll\\r\\nReport Id: b8cb8839-fbc6-4992-9ded-117bca245d14\\r\\nFaulting package full name: \\r\\nFaulting package-relative application ID: \\\"\"},\"eventdata\":{\"data\":\"SolarWinds.Orion.LogMgmt.SyslogService.exe, 2.2.0.14784, 5da00ff2, KERNELBASE.dll, 10.0.14393.1770, 59bf2ba6, e0434352, 0000000000033c58, 1290, 01d70fc5fa1c13e4, C:\\\\\\\\Program Files (x86)\\\\\\\\SolarWinds\\\\\\\\Orion\\\\\\\\OLM\\\\\\\\SolarWinds.Orion.LogMgmt.SyslogService.exe, C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll, b8cb8839-fbc6-4992-9ded-117bca245d14\"}}}\n{\"win\":{\"system\":{\"providerName\":\"Microsoft-Windows-PerfNet\",\"providerGuid\":\"{CAB2B8A5-49B9-4EEC-B1B0-FAC21DA05A3B}\",\"eventSourceName\":\"PerfNet\",\"eventID\":\"2006\",\"version\":\"0\",\"level\":\"2\",\"task\":\"0\",\"opcode\":\"0\",\"keywords\":\"0x80000000000000\",\"systemTime\":\"2021-03-03T00:40:56.714993200Z\",\"eventRecordID\":\"27549\",\"processID\":\"0\",\"threadID\":\"0\",\"channel\":\"Application\",\"computer\":\"agente1\",\"severityValue\":\"ERROR\",\"message\":\"\\\"Unable to read Server Queue performance data from the Server service. The first four bytes (DWORD) of the Data section contains the status code, the second four bytes contains the IOSB.Status and the next four bytes contains the IOSB.Information.\\\"\"},\"eventdata\":{\"binary\":\"230000C00000000000000000\"}}}",
"manager": {
"name": "srvwazuh"
},
"data": {
"win": {
"eventdata": {
"data": "SolarWinds.Orion.LogMgmt.SyslogService.exe, 2.2.0.14784, 5da00ff2, KERNELBASE.dll, 10.0.14393.1770, 59bf2ba6, e0434352, 0000000000033c58, 11d0, 01d70fc65c078919, C:\\\\Program Files (x86)\\\\SolarWinds\\\\Orion\\\\OLM\\\\SolarWinds.Orion.LogMgmt.SyslogService.exe, C:\\\\Windows\\\\System32\\\\KERNELBASE.dll, 9c346fd6-9807-4f58-b895-91c0e732b593"
},
"system": {
"eventRecordID": "27574",
"eventID": "1000",
"computer": "agente1",
"task": "100",
"keywords": "0x80000000000000",
"level": "2",
"severityValue": "ERROR",
"channel": "Application",
"message": "\"Faulting application name: SolarWinds.Orion.LogMgmt.SyslogService.exe, version: 2.2.0.14784, time stamp: 0x5da00ff2\r\nFaulting module name: KERNELBASE.dll, version: 10.0.14393.1770, time stamp: 0x59bf2ba6\r\nException code: 0xe0434352\r\nFault offset: 0x0000000000033c58\r\nFaulting process id: 0x11d0\r\nFaulting application start time: 0x01d70fc65c078919\r\nFaulting application path: C:\\Program Files (x86)\\SolarWinds\\Orion\\OLM\\SolarWinds.Orion.LogMgmt.SyslogService.exe\r\nFaulting module path: C:\\Windows\\System32\\KERNELBASE.dll\r\nReport Id: 9c346fd6-9807-4f58-b895-91c0e732b593\r\nFaulting package full name: \r\nFaulting package-relative application ID: \"",
"systemTime": "2021-03-03T00:44:47.917792800Z",
"providerName": "Application Error"
}
}
},
"rule": {
"firedtimes": 4,
"mail": true,
"level": 10,
"description": "Multiple Windows error Application events",
"groups": [
"windows",
"windows_application"
],
"id": "61061",
"frequency": 8
},
"decoder": {
"name": "windows_eventchannel"
},
"input": {
"type": "log"
},
"@timestamp": "2021-03-03T00:44:47.941Z",
"location": "EventChannel",
"id": "1614732287.762376582",
"timestamp": "2021-03-02T19:44:47.941-0500",
"_id": "M-aL9XcBgHToKSV3Z237"
}