To gather logs other than the default defined Windows Event logs, first create a custom Data Source.
1. In InTrust Manager expand Configuration and right click on Data Sources.
2. Select New Data Source and then the Data Source Type Microsoft Windows Events. Click Next.
3. Specify the Log name, best practice would be open the Properties of the desired log in Windows Event Viewer and copy the Full Name of the log, then paste the Full Name into the Log name: dialogue box.
4. Give the Data Source a descriptive name. Click Next
5. Click Finish
6. Now add the new custom Data Source in the appropriate Gathering Policy.