A negative lookahead is a powerful regex which allows you to match Everything, but omit certain things you do not want.
You can leverage SysEDGE autowatchers to monitor All Windows Services with an automatic startup type. In some instances you may want to exclude a handful of these services from the monitor.
This can be done with the following Regex:
^(?!Windows Time|Microsoft .NET).*
The above example would look for all Windows Services but exclude the "Windows Time" service, and any services that contain "Microsoft .NET"
This regex requires that the Base Policy has PCRE Enabled (use_pcre in sysedge.cf)
If you are managing SysEDGE hosts from VAIM this can be found within the Policy under Control Settings > miscellaneous:
"Use Perl Compatible Regular Expressions"
Once PCRE is enabled the policy needs to be deployed to the host(s) so the agent has PCRE enabled.
Here is a screenshot of how this monitor would be configured from within a VAIM Policy: