- Go to
Monitoring->Monitoring Packs & Policies. - Create
New Monitoring Pack. - Switch to
Alerting & Reportingtab and useAdd Alertbutton. - Select Windows tab and double-click on New Event for Received Windows Event Log Entry.
- In Alerting Rule window in Windows Event Log file field select
Security. - In Expression field select Event Identifier is equal and type 5025 as identifier. (5025 ID value corresponds to: The Windows Firewall service was stopped message).
- Assign nodes to this Monitoring Pack and save Monitoring Pack Settings.
You can find more descriptions of Windows security events here.