I want to filter out Warnings, but keep Errors and Critical events in Event Viewer for a particular event.
Does "EnableLevel"=dword:00000002
accomplish this?
For example
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\EventLog-System\{1c95126e-7eea-49a9-a3fe-a378b03ddb4d}]
"EnableLevel"=dword:00000002
; Default = 0, everything is logged
The Warning events I'm trying to filter from my System Log happen randomly and sometimes days between events, so it's very difficult to determine if changing the value actually works.
The docs seem to indicate that 2
is what I want to only log Error and Critical-level events.
From here
Microsoft defines the semantics of levels 1-5 as shown below.
| Value | Meaning |
|-----------------------------|--------------------------------------------|
| TRACE_LEVEL_CRITICAL (1) | Abnormal exit or termination events |
| TRACE_LEVEL_ERROR (2) | Severe error events |
| TRACE_LEVEL_WARNING (3) | Warning events such as allocation failures |
| TRACE_LEVEL_INFORMATION (4) | Non-error informational events |
| TRACE_LEVEL_VERBOSE (5) | Detailed diagnostic events |