Subscription XPath Filters
Example Scenarios and Queries¶
1. Filter by Event ID¶
To forward events with ID 6008 (shutdown events):
//*[local-name()='Event' and namespace-uri()='http://schemas.microsoft.com/win/2004/08/events' and @EventID='6008']
2. Combine Multiple Conditions¶
Forward events with ID 41 (service start) and level 4 (information):
//*[local-name()='Event' and namespace-uri()='http://schemas.microsoft.com/win/2004/08/events'
and @EventID='41' and @Level='4']
3. Filter by Event Data¶
Capture events where the Data field contains the string "ServiceController":
//*[local-name()='Event' and namespace-uri()='http://schemas.microsoft.com/win/2004/08/events'
and Data[contains(text(), 'ServiceController')]]
4. Exclude Specific Events¶
Avoid forwarding events with ID 6006 (logoff events):