Overview
This article will cover how to setup monitoring ThreatLockerService through Kaseya VSA.
Assign Event Set
- Under Agent Monitoring on the left-hand side menu, select ‘Event Log Alerts’
![undefined](https://cdn.livechat-static.com/api/file/kb/file/9686855/5d00e14334-910ea9baf30442f6fe9a.png)
- Check the box for the applicable Machine.Group ID
- In the Assign Event Set tab:
- Select event log type: Application
- Check the box for Information
- Define events to match or ignore: < New Event Set >
- In the popup window, enter the Event Set Name and click ‘New’
- Under the Source Filter, type ‘ThreatLockerService’, click ‘Add’, click ‘Deploy’, and then click ‘Close’
![undefined](https://cdn.livechat-static.com/api/file/kb/file/9686855/93d6de9c98-b9ccd42f904395f38f41.png)
![undefined](https://cdn.livechat-static.com/api/file/kb/file/9686855/98252f0f03-bb17263574983f194c8a.png)
- Check the box for the applicable Machine.Group ID
- Select your event from the Define events to match or ignore drop-down menu
![undefined](https://cdn.livechat-static.com/api/file/kb/file/9686855/0317d251d4-26cc018974196247dc4a.png)
Set Alert Actions
- Under the Set Alert Actions tab, check the box for Create Alarm and click ‘Apply’
![undefined](https://cdn.livechat-static.com/api/file/kb/file/9686855/224199fe2f-8bbd9bceb79a6033799a.png)
- The alert will show under the Email Address/Event Set column of the selected Machine.Group ID.
![undefined](https://cdn.livechat-static.com/api/file/kb/file/9686855/995a06affa-6935dc7f35531b9c1175.png)
Filter the Audit Logs to View ThreatLockerService
- Under the Audit and View Individual Data dropdowns on the left-hand side menu, select ‘Machine Summary’
- Under Agent Logs, in your search parameters select ‘Event Logs’ and ‘Application’, choose your start and end dates, and click ‘Filter’
- In the popup window, select all event categories, type in the name of your Event Source (this should match what you inputted for Source Filter), type in 0 as your Event ID, and click ‘Apply’
![undefined](https://cdn.livechat-static.com/api/file/kb/file/9686855/15dbfefbd9-576bef546016b0d619f0.png)
- ThreatLockerService appears when it initially starts or is restarted.
![undefined](https://cdn.livechat-static.com/api/file/kb/file/9686855/9770da7eab-8a0f43d10422322b5b57.png)