SCOM Event Log Alert E-Mail Incomplete

Joseph Setaro 121 Reputation points
2022-03-10T15:05:28.643+00:00

Hello,

I am running SCOM 2019, and I setup an alert to e-mail me when a certain process is created. The alert is working, however the alert is incomplete. The Event Log shows the path where the executable was created (Ex. New Process Name=C:\Steam\Steam.exe). The e-mail that I get shows "New Process Name=C". How do I get it to show the full path so I can determine if this is a false alert?

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,504 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. SChalakov 10,396 Reputation points MVP
    2022-03-23T10:41:26.647+00:00

    Hi,

    can you post a couple of screenshots, shwoing your subscription configuration. Are you using HTML enrichment?

    Thanks and Regards,
    Stoyan

    0 comments No comments

  2. Joseph Setaro 121 Reputation points
    2022-03-23T13:29:14.217+00:00

    Hello,
    186106-steamalert.png

    This is the alert response for the rule I created. I am monitoring an event that gets logged in the Security log, and I am looking for a specific word in the log. The log entry has a line that says "NewProcessName=C:\Steam\Steam.exe". This is what the e-mail shows: I tried HTML enrichment, and I get the same thing.

    Alert: MSSD-Blocked Program Alert-Steam
    Source: MyPC
    Path: Not Present
    Last modified by: System
    Last modified time: 3/22/2022 4:43:09 PM Alert description: Event Description: A new process has been created.

    Creator Subject:
    Security ID: DOMAIN\User
    Account Name: User
    Account Domain: DOMAIN
    Logon ID: 0xbbc6a

    Target Subject:
    Security ID: NULL SID
    Account Name: -
    Account Domain: -
    Logon ID: 0x0

    Process Information:
    New Process ID: 0x3330
    New Process Name: C
    Token Elevation Type: %%1936
    Mandatory Label: Mandatory Label\Medium Mandatory Level
    Creator Process ID: 0x24c4
    Creator Process Name: C
    Process Command Line:

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.