Edit Event Filtering page
Print
Copy page Copy as Markdown for LLMs View as Markdown View the page as plain text
Open in ChatGPT Ask ChatGPT about this page Open in Claude Ask Claude about this page Prev Next Use this page to specify which events are forwarded to the ePO - On-prem server.
Option definitions
Option
Definition
The agent forwards
Specifies, globally, which events the agent processes and forwards to the ePO - On-prem server. Options include:
All events to the server — Process and forward all events to the server.
To individually select the server or servers to receive the events, select one of these options:
Store in ePO —Stores the event in the ePO - On-prem database.
Store in SIEM —Stores the event in the SIEM database.
Store in both —Stores the event in ePO - On-prem and SIEM databases.
To globally select the server or servers to receive the events, select one of these options:
Store selected in ePO —Store all selected events in ePO - On-prem database.
Store selected in SIEM —Store all selected events in SIEM database.
Store selected in both —Store all selected events in ePO - On-prem and SIEM databases. The default setting.
Select All and Deselect All are disabled when you select All events to the server .
Only selected events to the server — Process and forward only those events selected from the list of available events.
To individually select the server or servers to receive the individual events, select one of these options:
Store in ePO —Stores the event in the ePO - On-prem database.
Store in SIEM —Stores the event in the SIEM database.
Store in both —Stores the event in ePO - On-prem and SIEM databases.
To globally select the server or servers to receive the individually selected events, select one of these options:
Store selected in ePO —Store all selected events in ePO - On-prem database.
Store selected in SIEM —Store all selected events in SIEM database.
Store selected in both —Store all selected events in ePO - On-prem and SIEM databases. The default setting.
You can use Select All and Deselect All , with Only selected events to the server , to select or deselect the all event checkboxes.
These settings do not take effect until the next agent-server communication.
The server accepts
Specifies, globally, events accepted by the ePO - On-prem server. Options include:
Events from any source — All events sent by any agent are process by the ePO - On-prem server. The default setting.
Events that were generated by the sending agent — The ePO - On-prem server processes only those events sent by the source agent.
Was this article helpful?
Yes No
Related articles
Data Loss Prevention (DLP) > Data Loss Prevention SaaS > Trellix Data Loss Prevention - SaaS Product Guide - February 2026 > Setting up automatic responses when events occur
ePolicy Orchestrator - On-Prem > ePolicy Orchestrator - On-prem 5.10.0 Product Guide > Setting up automatic responses > Determine how events are forwarded
Data Loss Prevention (DLP) > Data Loss Prevention SaaS > Trellix Data Loss Prevention - SaaS Product Guide - February 2026 > Setting up automatic responses when events occur > Determine how events are forwarded