Appearance
Event log collection
Windows agents continuously collect Critical and Error entries from the Application and System event logs and send them to OpsMerge, so you can see what has been going wrong on a device without connecting to it. Collection is automatic on every Windows agent - there is nothing to enable.
The Security log is not collected, and Warning and Information entries are not collected. For an ad-hoc look at anything else, the live Event Log query on the device page still queries the endpoint directly.
What you see
Open a device and go to the Event Log tab. The Collected errors panel at the top shows the last 4 days, grouped by recurring event: one row per distinct combination of log, source, event ID and severity, with:
- a count of how often it fired,
- first seen and last seen times,
- up to three sample messages - click a row to expand them.
Grouping is the point: a service that crashed 4,000 times shows as one row with a count of 4,000, not 4,000 rows. The panel answers "what is wrong with this machine" at a glance.
Filter by severity or source, and use the refresh button to pick up the newest collection cycle. Agents report roughly every 15 minutes.
Retention
Collected entries are kept for 4 rolling days, then removed automatically. This window is deliberately short - the feature is a forensic aid, not an archive.
Keeping evidence longer: extended capture
When you are investigating an ongoing problem, turn on Extended capture from the panel header and pick 7, 14 or 30 days. While it is on, new collections for that device are also kept for the chosen period, marked with a Pinned badge. Tick Include extended-capture rows to see them alongside the live window.
Extended capture switches itself off at the end of the chosen period. Turning it off early stops new pinning but does not delete what was already kept - pinned entries age out on their own schedule. Requires the agents.event_logs.manage permission.
AI analysis
If your organisation has an AI key configured (Settings → AI), the Analyse with AI button sends a digest of the device's collected errors - the most frequent groups, with one sample each - to your configured AI provider and returns an assessment: likely root causes, related events grouped together, anything urgent, and suggested next steps.
Notes:
- The digest goes to your configured provider under your own key, like the other AI features.
- Calls are metered under the daily
event_log_analyzeallowance (Settings → AI shows usage). - Event log messages can contain usernames, hostnames and file paths. If that should not leave your estate, disable the feature in Settings → AI - the panel itself keeps working without it.
Limits worth knowing
- Windows only for now. On other platforms the panel explains this; nothing is collected.
- Messages are truncated to 2 KB per sample.
- Under an event flood, the agent keeps the most recent entries and the counts still reflect what it read; the batch is marked truncated internally.
- Collected entries never create alerts or tickets. Alerting on event log conditions is done with Event Log checks, which are separate and configurable per policy.