Edit Event SetsEdit Event Sets let you filter the monitoring of events in Application, Security, and System event logs maintained by the Windows OS of a managed machine. Events matching an event set can trigger an alert or suppress the triggering of an alert when the Ignore checkbox is checked. You can assign multiple event sets to a machine ID. If any one of a multiple number of event set rows are detected, then the event is included. Any one of a multiple number of Ignore event set rows override ALL included event set rows, if applicable. Note: You can display event logs directly. On a Windows machine click Start, then click Control Panel, then click Administrative Tools, then click Event Viewer. Click Application, Security or System to display the events in that log. Double-click an event to display its Properties window. You can copy and paste text from the Properties window of any event into Edit Event Set fields. Event sets are specified using one or more of the following event properties.
To Create a New Event Set
Ignore The Ignore checkbox enables you to trigger an alert for all events except for the events you want to ignore. Ignore events always take precedence over other event sets. You must assign multiple event sets to the same machine ID to make use of of the Ignore feature. Example:
If any one of a multiple number of include event set rows are detected, then the event is included. If any one of a multiple number of Ignore event set rows are detected, it overrides all included event set rows, if applicable. Using the Asterisk (*) Wildcard Using the asterisk (*) wildcard you can create a filter for multiple events. For example: *yourFilterWord1*yourFilterWord2* This would match and raise an alarm for an event with the following string: "This is a test. yourFilterWord1 as well as yourFilterWord2 are in the description." Exporting and Importing Edit Events You can export and import event set records as XML files.
Example: <?xml version="1.0" encoding="ISO-8859-1" ?> | ||
Topic 2886: Send Feedback |