Setting up EVENTMON Please follow the below steps to setup captures based on the Event Id. On the node, enabled network trace using the command below:
Open a command prompt using elevated privilege and run the below command Netsh trace start persistent=yes capture=yes report=yes overwrite=yes maxsize=1024 tracefile=c:\net.etl Right click event and select “Attach a task to this event” Name the task and click next twice Select “Start a program” -> Next Type “Netsh” on Program texts box and “trace stop” in the arguments window as shown below -> Next
Select “Open the Properties dialog for this task when I click Finish” option and select the option “Run whether user is logged on or not” and “Run with highest privilege” -> OK