I am having a lot of trouble getting this to work. I have created a template and an item with the following key: eventlog[Microsoft-Windows-Windows Defender/Operational,,,5001]... I can't seem to get a trigger to monitor this correctly? Can someone help with this? I need the trigger to monitor for this log so that it can alert via email if Defender RTP has been turned off