Prune routine system-generated events not relevant for monitoring or auditing.
This wizard helps you exclude or ignore events not required to meet compliance requirements based on rules using a combination of one or more parameters. The Events Exclusion wizard displays when you select the Exclude Events action for selected events on the Solidcore Events page.
Option definitions
Option
Definition
Prepopulated rules
Exclusion rules are auto-populated for all events selected on the Solidcore Events page. Review and refine existing rules, as needed.
Add Rule
Adds new event filtering rule. Configure these options as required.
File — Specifies the comparison operator and file name or directory to be excluded from being monitored.
Event — Specifies the comparison operator and Solidcore event to be excluded from being monitored.
Program — Specifies the comparison operator and process or program to be excluded from being monitored.
Registry — Specifies the comparison operator and registry key to be excluded from being monitored. This option is available only for the Windows platform.
User — Specifies the comparison operator and user name to be excluded from being monitored.
Note
When using the equals operator, specify the fully qualified path (for example, C:\windows\regedit.exe). When using other operators, such as ends with or contains, specify the partial path (for example, regedit.exe). The comparisons are case-sensitive for UNIX and case-insensitive for Windows.
Apply rule to events also
Applies the defined set of rules to filter events. If you select this option, the filter rules are applied to both observations and events. This option is available only for Application Control rule groups.
Delete
Deletes the selected rule.
Back
Moves to the previous page of the wizard.
Next
Moves to the next page of the wizard.
Cancel
Exits without saving changes and return to the Solidcore Events page.
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Interface Reference
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Interface Reference
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Interface Reference