C:\WINDOWS>EVENTCREATE /?
EVENTCREATE
[/S system
[/U username
[/P
[password
]]]] /ID eventid
[/L logname
] [/SO srcname
] /T type /D description
Description:
This command line tool enables an administrator to create
a custom event ID and message in a specified event log.
Parameter List:
/S system Specifies the remote system to connect to.
/U
[domain\
]user Specifies the user context under which
the command should execute.
/P
[password
] Specifies the password for the given
user context. Prompts for input if omitted.
/L logname Specifies the event log to create
an event in.
/T type Specifies the type of event to create.
Valid types: ERROR, WARNING, INFORMATION.
/SO source Specifies the source to use for the
event. A valid source can be any string
and should represent the application or
component that is generating the event.
/ID id Specifies the event ID for the event. A
valid custom message ID is in the range
of 1 - 1000.
/D description Specifies the description to be set for
the newly creating event.
/? Displays this help/usage.
Examples:
EVENTCREATE /T ERROR /ID 100
/L APPLICATION /D "Create an event in application log"
EVENTCREATE /T ERROR /ID 999 /L APPLICATION
/SO WinWord /D "new source Winword in application log"
EVENTCREATE /S system /T ERROR /ID 100
/L APPLICATION /D "Remote system without user credentials"
EVENTCREATE /S system /U user /P password /ID 100 /T ERROR
/L APPLICATION /D "Remote machine with user credentials"
EVENTCREATE /S system /U domain\user /ID 100 /T WARNING
/SO MyBatchFile.cmd /D "Maintenance script user logon failed"
C:\WINDOWS>EVENTTRIGGERS /?
EVENTTRIGGERS /parameter
[arguments
]Description:
This command-line tool enables an administrator to display and
configure "Event Triggers" on local or remote system.
Parameter List:
/Create Create a new Event Trigger that will monitor and act
upon the occurrence of NT Log Events of given criteria.
/Delete Deletes an Event Trigger by its trigger ID.
/Query Displays the Event Trigger properties and settings.
/? Displays this help/usage.
Examples:
EVENTTRIGGERS /Create /?
EVENTTRIGGERS /Delete /?
EVENTTRIGGERS /Query /?
C:\WINDOWS>EVENTTRIGGERS /CREATE /?
EVENTTRIGGERS /Create
[/S system
[/U username
[/P
[password
]]]] /TR triggername /TK taskname
[/D description
] [/L log
] [/RU username
[/RP
password
]]Description:
Create a new Event Trigger that will monitor and act upon the
occurrence of NT Log Events of a given criteria.
NOTE: Using /EID, /T and /SO together act as a series of AND's.
Parameter List:
/S system Specifies the remote system to connect to.
/U
[domain\
]user Specifies the user context under which the
command should execute.
/P
[password
] Specifies the password for the given user
context. Prompts for input if omitted.
/TR triggername Specifies a friendly name to associate with
the Event Trigger.
/L log Specifies the NT Event Log(s) to monitor
events from. Valid types include:
Application, System, Security, DNS Server
Log and Directory Log. The wildcard "*"
may be used and the default value is "*".
/EID id Specifies a specific Event ID the Event
Trigger should monitor for.
/T type Specifies an Event Type that the trigger
should monitor for. Valid values include:
"ERROR", "INFORMATION", "WARNING",
"SUCCESSAUDIT" and "FAILUREAUDIT".
/SO source Specifies a specific Event Source the Event
Trigger should monitor for.
/D description Specifies the description of the Event
Trigger.
/TK taskname Specifies the task to execute when the
Event Trigger conditions are met.
/RU username Specifies the user account (user context)
under which the task runs. For the system
account value must be "".
/RP password Specifies the password for the user.
To prompt for the password, the value
must be either "*" or none.
Password will not effect for the "SYSTEM"
account.
/? Displays this help/usage.
Examples:
EVENTTRIGGERS /Create /?
EVENTTRIGGERS /Create /TR "Disk Cleanup" /L SYSTEM /T ERROR
/TK c:\windows\system32\cleanmgr.exe
EVENTTRIGGERS /Create /S system /U user /TR "Low Disk Space"
/EID 4133 /T WARNING
/TK \\srv\share\dsk.cmd
EVENTTRIGGERS /Create /S system /U domain\user /P password
/TR "Disk Backup" /EID 4133 /L SYSTEM
/T ERROR /TK \\system\share\ntbackup.exe
EVENTTRIGGERS /Create /RU user /RP password /TR "Disk Backup"
/TK \\system\share\ntbackup.exe /EID 4