Hi
Usually I perform
"select * on logsourcename(logsourceid) where logsourcename(logsourceid) ilike "%logsourcename%" group by logsourcename(logsourceid) " asc if you need limit if you need. I'm not on a computer right now so the syntax maybe checked.
Once you have the logsource information you can filter out the information with qidname(qid) and that should give you the different events. I start with * cause if we filter fields that have been parsed we may not see the information.
then once you have that you can categorise the events sort them usually by qid , message , payload even. the data is usually there
This was worked on numerous times with Wincollect with good results. The wincollect errors are not usually parsed but their in the payload.
Syslog as I see you have configured your mileage may vary but it's worth a shot.
I've found found often the data just isn't parsed properly so you have to dig for it.
You can also query the health monitoring DSM and you might find errors there as well such as connectivity issues but the host will send actual errors if possible. Each vendor is different.
You may find that there are no good information to use but it might be there.
I hope this helps.
Thank you
Jon