In the Provider name, type Netlogon, and in the Provider log type drop-down
list, select Generic Single-line log file. In the Directory Edit dialog box type
%Systemroot%\debug in the Directory text box and select Generic in the
Format drop-down menu. Click Add as shown in Figure 5.21.
Figure 5.21 Directory Edit
In the File Pattern section of the Directory Edit dialog box shown in Figure
5.21, type netlogon.log. Now that the new provider has been created, you can
create a new event collection rule that collects events logged in the
%Systemroot%\debug\netlogon.log file.
To do this, open the Administrator Console and expand the Management Packs
node. Create ...