Hello,
This problem is because you have defined both, eventchannel and eventlog. When you have defined both, eventlog would be ignored and rules will be fired with the events from eventchannel.
Hello,
netsh.exe and route-null.exe keep expecting srcip information, but they aren’t able to read it from events coming from eventchannel. There is an issue opened to solve this, you can track it here. Until it is solved, you’ll need to use eventlog if you want to trigger those active responses.