Figure 1: Sample evtfwd.con
# Type, Source, Computer, and Target expect strings while Category,
#EventID, and Priority expect integer values.
#
#Type Source Category EventID Computer Target Priority
#---- ------ -------- ------- -------- ------ --------
EVENTLOG_INFORMATION_TYPE [a-zA-Z]+ [0-9] [0-9]+ [a-zA-Z_]+ tweedle 14
EVENTLOG_WARNING_TYPE [a-zA-Z]+ [0-9] [0-9]+ [a-zA-Z_]+ tweedle 12
EVENTLOG_ERROR_TYPE [a-zA-Z]+ [0-9] [0-9]+ [a-zA-Z_]+ tweedle 11
EVENTLOG_AUDIT_SUCCESS [a-zA-Z]+ [0-9] [0-9]+ [a-zA-Z_]+ tweedle 38
EVENTLOG_AUDIT_FAILURE [a-zA-Z]+ [0-9] [0-9]+ [a-zA-Z_]+ tweedle 36
|