General Filter Options |
Top Previous Next |
You can filter against every field of an event log record except the Computername (which is assumed to be the localhost) and the Date and Time (you can filter based on hour and day, please see Day & Hour Configuration on the next page for details).
Detailed Field Descriptions:
Name The filter name is chosen by you and can be any text no longer than 128 characters. Filter names must be unique. The filter name may not contain a backslash (\).
Group The group this filter belongs to. To change this move the filter to a different group.
Targets All targets that are to be notified (include filter) or not to be notified (exclude filter) when this filter matches.
Apply to all targets Check this checkbox to notify all configured targets instead of selected ones.
Event Severity Select which types of events this filter should match. "Audit Success" and "Audit Failure" are only relevant when you also monitor the security event log.
Log Select which event log(s) this filter should monitor. The event logs, "Directory Service" and "File Replication (Service)," are only useful on Windows 2000 (and higher) domain controllers. The event log "DNS Server" is only useful on Windows 2000 servers (and higher) when a DNS server is installed.
Event Source Specify which source this filter should match. If you do not specify an event source, the filter will match any source.
Event Category Specify which category this filter should match. If you do not specify an event category, the filter will match any category.
Event ID Specify which Event ID this filter should match. You can separate multiple Event IDs with a comma, for example "3,5,118".
Username Specify which username this filter should match. This is currently only relevant for the security event log. Usernames are logged by the Operating System in the form DOMAIN\Username.
Computer Specify which computer this filter should match. If you do not specify a computer name, the filter will match any computer.
Filter Type
Stop processing other filters If you check this box then this filter will be the last to process this record, even if it is not the last one in the list.
Filter Text If you would like to filter against a certain text string instead of or in addition to the properties listed above, you can utilize the Filter Text field. Type any text you want the filter to match in the actual event description, you can separate multiple strings with a comma (make sure there are no spaces after the comma). To include the comma as a text filter itself type it twice (e.g. "event description, something else"). This field is case insensitive (since v1.15).
This field behaves differently depending on whether wildcard support (configure in "Service Options") is activated or not:
Wildcard Support Not Active: EventSentry will check whether one of the strings you specified will occur in the event description, a 1:1 match is not required.
Wildcard Support Active: Please see Wildcard Support for details. You will need to either use wildcards or specify an exact 1:1 match in this case.
Day and Time Restrictions Please see the Day & Hour page for details. |