The opinion was that there may have been many events filtered out that we were missing, as we had a fairly old install with many exclusions.
What is the best way to approach a new install and get most of the critical alerts?
I've just re-installed in the hope that we can get eventsentry to a default state where we can decide which events we don't want as we get them. Possibly not the best approach, but this is what has been requested.
It seems to exclude events, and the requirement is you add the filters as required?