|
Navigation: Monitoring with EventSentry > Event Log Monitoring > Filters > Advanced Text Processing |
|
|
Comma Separated Values (Event Log Filters only) You can separate multiple values with a comma to avoid creating multiple filters. Simply combine all the values the field should match with commas and make sure you are not using a space after or before the comma. For example:
Print,MrxSmb
All fields in the "Details" section and the "Filter Text" support this feature.
Negation Symbol (Event Log Filters only) You can negate a value by pre pending it with an exclamation mark. For example, to match all events except for those with the source of Print you could use the following:
Wildcard Feature When Wildcard Support is activated in the global options then the following filter fields support wildcards:
Event Log Filters 1. Event Source 2. Category 3. Username 4. Filter Text
Service Monitoring 1. Included/Excluded Service
Tracking Features 1. Included/Excluded Process 2. Included/Excluded Logons 3. Included/Excluded Print Jobs
The wildcards * and ? are currently supported.
Examples
|