I need to parse a new windows event using ESI, the problem i can not find the Windows table to select events from, i found Windows accounting and windows level tables just.
In my reports i am using windows tables so any event i parsed ito the previous tables does not included in my reports! what could i do?
If you have installed ESI, you require to update the content as well to bring t to the Content 2 level. After updating it will give you the Windows Table. Her eis what you need to do.
1. Download the latest ESU from RSA SCOL site.
2. On the machine where you have installed ESI, please run the following command
<file path>\<ESU file name> -update_esi
Follow the steps and boom it'll update all the contents for ESI and you'll be able to find the Content 2 tables.
To enable the Windows table for your message on your ESI:
Go to File --> Preference --> RSA enVision Tables select/tick Show All
Click Apply to save
This will make all tables available for your selected Event Source Class.