<ViewerConfig><QueryConfig><QueryParams><Simple><Level>1,2,3</Level><Channel>Application,Security,System,DFS Replication,Doctor Web,HardwareEvents,Internet Explorer,Key Management Service,Microsoft-Windows-Application Server-Applications/Admin,Microsoft-Windows-RemoteAssistance/Admin,Windows PowerShell</Channel></Simple></QueryParams><QueryNode><Name>Administrative Events</Name><Description>Critical, Error and Warning events from all administrative logs</Description><QueryList><Query Id="0" Path="Application"><Select Path="Application">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="Security">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="System">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="DFS Replication">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="Doctor Web">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="HardwareEvents">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="Internet Explorer">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="Key Management Service">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="Microsoft-Windows-Application Server-Applications/Admin">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="Microsoft-Windows-RemoteAssistance/Admin">*[System[Level=1  or Level=2 or Level=3]]</Select><Select Path="Windows PowerShell">*[System[Level=1  or Level=2 or Level=3]]</Select></Query></QueryList></QueryNode></QueryConfig><ResultsConfig><Columns><Column Name="Level" Type="System.String" Path="Event/System/Level" Visible="">279</Column><Column Name="Keywords" Type="System.String" Path="Event/System/Keywords">70</Column><Column Name="Date and Time" Type="System.DateTime" Path="Event/System/TimeCreated/@SystemTime" Visible="">329</Column><Column Name="Source" Type="System.String" Path="Event/System/Provider/@Name" Visible="">239</Column><Column Name="Event ID" Type="System.UInt32" Path="Event/System/EventID" Visible="">239</Column><Column Name="Task Category" Type="System.String" Path="Event/System/Task" Visible="">241</Column><Column Name="User" Type="System.String" Path="Event/System/Security/@UserID">50</Column><Column Name="Operational Code" Type="System.String" Path="Event/System/Opcode">110</Column><Column Name="Log" Type="System.String" Path="Event/System/Channel">80</Column><Column Name="Computer" Type="System.String" Path="Event/System/Computer">170</Column><Column Name="Process ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessID">70</Column><Column Name="Thread ID" Type="System.UInt32" Path="Event/System/Execution/@ThreadID">70</Column><Column Name="Processor ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessorID">90</Column><Column Name="Session ID" Type="System.UInt32" Path="Event/System/Execution/@SessionID">70</Column><Column Name="Kernel Time" Type="System.UInt32" Path="Event/System/Execution/@KernelTime">80</Column><Column Name="User Time" Type="System.UInt32" Path="Event/System/Execution/@UserTime">70</Column><Column Name="Processor Time" Type="System.UInt32" Path="Event/System/Execution/@ProcessorTime">100</Column><Column Name="Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@ActivityID">85</Column><Column Name="Relative Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@RelatedActivityID">140</Column><Column Name="Event Source Name" Type="System.String" Path="Event/System/Provider/@EventSourceName">140</Column></Columns></ResultsConfig></ViewerConfig>