Events Exclusion wizard — Define Rules page

Prev Next

Prune routine system-generated events not relevant for monitoring or auditing.

This wizard helps you exclude or ignore events not required to meet compliance requirements based on rules using a combination of one or more parameters. The Events Exclusion wizard displays when you select the Exclude Events action for selected events on the Solidcore Events page.

Option definitions

Option

Definition

Prepopulated rules

Exclusion rules are auto-populated for all events selected on the Solidcore Events page. Review and refine existing rules, as needed.

Add Rule

Adds new event filtering rule. Configure these options as required.

  • File — Specifies the comparison operator and file name or directory to be excluded from being monitored.

  • Event — Specifies the comparison operator and Solidcore event to be excluded from being monitored.

  • Program — Specifies the comparison operator and process or program to be excluded from being monitored.

  • Registry — Specifies the comparison operator and registry key to be excluded from being monitored. This option is available only for the Windows platform.

  • User — Specifies the comparison operator and user name to be excluded from being monitored.

Note

When using the equals operator, specify the fully qualified path (for example, C:\windows\regedit.exe). When using other operators, such as ends with or contains, specify the partial path (for example, regedit.exe). The comparisons are case-sensitive for UNIX and case-insensitive for Windows.

Apply rule to events also

Applies the defined set of rules to filter events. If you select this option, the filter rules are applied to both observations and events. This option is available only for Application Control rule groups.

Delete

Deletes the selected rule.

Back

Moves to the previous page of the wizard.

Next

Moves to the next page of the wizard.

Cancel

Exits without saving changes and return to the Solidcore Events page.