Define filters for observations and events

Prev Next

You can specify advanced exclusion filters to exclude non-meaningful observations and events from the endpoints.

  1. On the ePO - SaaS console, create or change an Application Control policy or rule group.

  2. Select the Filters tab and expand Observations & Events.

  3. Click Add Rule to add a filter row.

    You can create filters based on files, events, programs, registry keys, and users. By default, all defined filters are applied to observations.

  4. Edit the settings to specify the filter.

  5. Click + or Add Rule to specify additional AND or OR conditions, respectively.

  6. Select Apply rule to events also for a set of rules to apply the filter rules to events.

    You can also define advanced exclusion filters from the Solidcore Events page.