<?xml version="1.0" encoding="UTF-8"?>
<!-- 
    Filtro dos logs do Windows Update no Visualizador de Eventos do Windows
    Este arquivo configura a visualização dos eventos relacionados ao Windows Update Client
    no Event Viewer, filtrando eventos do canal System com fonte Microsoft-Windows-WindowsUpdateClient
    Para importar o log, executando no path deste xml, utilize o comando:
        copy "WindowsUpdateLogs.xml" "%ProgramData%\Microsoft\Event Viewer\Views\filtroLogsWindowsUpdate.xml"
-->
<ViewerConfig>
    <QueryConfig>
        <QueryParams>
            <Simple>
                <Channel>System</Channel>
                <RelativeTimeInfo>0</RelativeTimeInfo>
                <Source>Microsoft-Windows-WindowsUpdateClient</Source>
                <BySource>False</BySource>
            </Simple>
        </QueryParams>
        <QueryNode>
            <Name>WindowsUpdate</Name>
            <QueryList>
                <Query Id="0" Path="System">
                    <Select Path="System">*[System[Provider[@Name='Microsoft-Windows-WindowsUpdateClient']]]</Select>
                </Query>
            </QueryList>
        </QueryNode>
    </QueryConfig>
    <ResultsConfig>
        <Columns>
            <Column Name="Nível" Type="System.String" Path="Event/System/Level" Visible="">158</Column>
            <Column Name="Palavras-chave" Type="System.String" Path="Event/System/Keywords">70</Column>
            <Column Name="Data e Hora" Type="System.DateTime" Path="Event/System/TimeCreated/@SystemTime" Visible="">208</Column>
            <Column Name="Fonte" Type="System.String" Path="Event/System/Provider/@Name" Visible="">118</Column>
            <Column Name="Identificação do Evento" Type="System.UInt32" Path="Event/System/EventID" Visible="">118</Column>
            <Column Name="Categoria da Tarefa" Type="System.String" Path="Event/System/Task" Visible="">122</Column>
            <Column Name="Usuário" Type="System.String" Path="Event/System/Security/@UserID">50</Column>
            <Column Name="Código Operacional" Type="System.String" Path="Event/System/Opcode">110</Column>
            <Column Name="Log" Type="System.String" Path="Event/System/Channel">80</Column>
            <Column Name="Computador" Type="System.String" Path="Event/System/Computer">170</Column>
            <Column Name="Identificação do Processo" Type="System.UInt32" Path="Event/System/Execution/@ProcessID">70</Column>
            <Column Name="Identificação de Thread" Type="System.UInt32" Path="Event/System/Execution/@ThreadID">70</Column>
            <Column Name="Identificação do processador" Type="System.UInt32" Path="Event/System/Execution/@ProcessorID">90</Column>
            <Column Name="Identificação da Sessão" Type="System.UInt32" Path="Event/System/Execution/@SessionID">70</Column>
            <Column Name="Tempo do Kernel" Type="System.UInt32" Path="Event/System/Execution/@KernelTime">80</Column>
            <Column Name="Tempo do Usuário" Type="System.UInt32" Path="Event/System/Execution/@UserTime">70</Column>
            <Column Name="Tempo do Processador" Type="System.UInt32" Path="Event/System/Execution/@ProcessorTime">100</Column>
            <Column Name="ID de Correlação" Type="System.Guid" Path="Event/System/Correlation/@ActivityID">85</Column>
            <Column Name="ID de Correlação Relativa" Type="System.Guid" Path="Event/System/Correlation/@RelatedActivityID">140</Column>
            <Column Name="Nome de Origem do Evento" Type="System.String" Path="Event/System/Provider/@EventSourceName">140</Column>
        </Columns>
    </ResultsConfig>
</ViewerConfig>