Applications Systems

Display Windows Event Log Monitor messages within alert emails in SAM

Learn how to display details about Windows Event Log Monitor messages in the body of emails triggered by alerts configured for SolarWinds SAM.

First published date

11/29/2018 10:29 PM

Last published date

12/23/2025 5:36 PM

Overview

This article describes how to display log messages in emails that are triggered by alerts configured for Windows Event Log Monitors in SAM. Instructions appear below.

A Windows Event Log Monitor is a specific type of component monitor; other types include Performance Counter Monitors and Windows Service Monitors. To learn more, see Work with SAM Component monitors

Here are additional documentation links about component monitors and alerts: 



 

Product section

Server Application Monitor

Resolution

  1. Open the SolarWinds Platform Web Console.
  2. Go to Settings > All Settings.
  3. In the Alerts & Reports group, click Manage Alerts.
  4. In the Alert Manager toolbar, click Add New Alert.
  5. Complete the Alert Properties, and then click Next to advance to the trigger condition settings.
  6. In the Trigger Conditions:
    1. From the I want to alert on drop-down menu, select Component.
    2. Trigger Alert when all child conditions must be satisfied (AND)
      • Component Status is equal to Down
      • Component Type is equal to 42 (This will filter it down to Trigger on Windows Event Monitors)
  7. Go to the Trigger Actions and add your Email Action.
  8. Use the following variable:
    ${N=SwisEntity;M=ComponentAlert.WindowsEventMessages}