Skip to content

Subscription XPath Filters

Example Scenarios and Queries

1. Filter by Event ID

To forward events with ID 6008 (shutdown events):

//*[local-name()='Event' and namespace-uri()='http://schemas.microsoft.com/win/2004/08/events' and @EventID='6008']

2. Combine Multiple Conditions

Forward events with ID 41 (service start) and level 4 (information):

//*[local-name()='Event' and namespace-uri()='http://schemas.microsoft.com/win/2004/08/events' 
and @EventID='41' and @Level='4']

3. Filter by Event Data

Capture events where the Data field contains the string "ServiceController":

//*[local-name()='Event' and namespace-uri()='http://schemas.microsoft.com/win/2004/08/events' 
and Data[contains(text(), 'ServiceController')]]

4. Exclude Specific Events

Avoid forwarding events with ID 6006 (logoff events):

//*[local-name()='Event' and namespace-uri()='http://schemas.microsoft.com/win/2004/08/events' 
and not(@EventID='6006')]