Define advanced exclusion filters to exclude observations, events, and inventory data by using a combination of conditions.
You can designate a set of files, events, processes or programs, registry keys, and users to exclude from being reported in observations and events. Also, you can designate a set of files, file types, files signed by certificates, application names, application versions, and application vendors to exclude from the inventory.
When using the equals operator, specify the fully qualified path (for example, C:\windows\regedit.exe). When using other operators, such as ends with or contains, specify the partial path (for example, regedit.exe). The comparisons are case-insensitive for Windows.
Option definitions
Option | Definition |
|---|
Observations & Events | Adds new advanced filtering rules for observations and events. Click Add Rule to configure these options as needed. File — Specifies the comparison operator and file name or directory to exclude. Event — Specifies the comparison operator and Solidcore event to exclude. Program — Specifies the comparison operator and process or program to exclude. Registry — Specifies the comparison operator and registry key to exclude. User — Specifies the comparison operator and user name to exclude.
|
Apply rule to events also | Applies the defined set of rules to filter events. If you select this option, the filter rules are applied to both observations and events. |
Delete | Deletes the selected advanced filtering rule. |
Inventory | Adds new advanced filtering rules for inventory data. Click Add Rule to configure these options as needed. File — Specifies the comparison operator and file name or directory to exclude. File type — Specifies the comparison operator and file types, such as executable file (32-bit or 64-bit) or script to exclude. Application name — Specifies the comparison operator and application name to exclude. Application version — Specifies the comparison operator and application version to exclude. Application vendor — Specifies the comparison operator and vendor (who builds the application) to exclude. This implies that all applications made by the specified vendor are excluded. File signed by certificate — Specifies that all signed files (signed by any certificate) are to be excluded.
When you create a filter to exclude inventory items based on the application name, version, or vendor, the filter works on the embedded values associated with the application.
|
Events | Adds new advanced filtering rules for events. Click Add Rule to configure these options as needed. File - Specifies the comparison operator and file name or directory to exclude. Event - Specifies the comparison operator and Solidcore event to exclude. Program - Specifies the comparison operator and process or program to exclude. Registry - Specifies the comparison operator and registry key to exclude. User - Specifies the comparison operator and user name to exclude.
|