Create or change monitoring rules

Prev Next

You can perform these actions when creating or changing a monitoring policy or rule group.

Task

  1. Monitor files and directories.
    1. On the File tab, click Add.
    2. In the Add File dialog box, specify the file or directory name.
    3. Indicate whether to include or exclude from monitoring.
    4. (Optional) To track content and attribute changes for a file, select Enable Content Change Tracking.
    5. Click OK.
  2. Monitor specific file types.
    1. On the Extension tab, click Add to open the Add Extension dialog box.
    2. Type the file extension. Don't include the period (dot) in the extension. For example, log.
    3. Indicate whether to include or exclude from monitoring and click OK.
  3. Monitor program activity.
    You can choose to track or not track file changes made by a specific program.
    1. On the Program tab, click Add to open the Add Program dialog box.
    2. Enter the name or full path of the program.
    3. Indicate whether to include or exclude from monitoring and click OK.
  4. Choose users you don't want to monitor.
    All changes made by this user aren't tracked.
    1. On the User tab, click Add to open the Add User dialog box.
    2. Specify the user name.
    3. Click OK.
  5. Specify advanced exclusion filters for events.
    1. On the Filters tab, click Add Rule to add a filter row.
    2. Edit the settings to specify the filter.
    3. Click + or Add Rule to specify additional OR conditions or AND conditions.
  6. Review predefined monitoring rules.
    1. Select MenuPolicyPolicy Catalog.
    2. Select the Solidcore 8.x.x: Integrity Monitor product.
    3. Open the relevant Minimal System Monitoring policy.
    4. Select a rule group in the Rule Groups pane to review the filters included in the rule group, then click Cancel.
    By default, these filters are applied to the global root in the System Tree and are inherited by all Trellix ePO - On-prem-managed endpoints where Change Control is installed.