Edit Event Filtering page

Prev Next

Use this page to specify which events are forwarded to the ePO - On-prem server.

Option definitions

Option

Definition

The agent forwards

Specifies, globally, which events the agent processes and forwards to the ePO - On-prem server. Options include:

  • All events to the server — Process and forward all events to the server.

    To individually select the server or servers to receive the events, select one of these options:

    • Store in ePO—Stores the event in the ePO - On-prem database.

    • Store in SIEM—Stores the event in the SIEM database.

    • Store in both—Stores the event in ePO - On-prem and SIEM databases.

    To globally select the server or servers to receive the events, select one of these options:

    • Store selected in ePO—Store all selected events in ePO - On-prem database.

    • Store selected in SIEM—Store all selected events in SIEM database.

    • Store selected in both—Store all selected events in ePO - On-prem and SIEM databases. The default setting.

    Note

    Select All and Deselect All are disabled when you select All events to the server.

  • Only selected events to the server — Process and forward only those events selected from the list of available events.

    To individually select the server or servers to receive the individual events, select one of these options:

    • Store in ePO—Stores the event in the ePO - On-prem database.

    • Store in SIEM—Stores the event in the SIEM database.

    • Store in both—Stores the event in ePO - On-prem and SIEM databases.

    To globally select the server or servers to receive the individually selected events, select one of these options:

    • Store selected in ePO—Store all selected events in ePO - On-prem database.

    • Store selected in SIEM—Store all selected events in SIEM database.

    • Store selected in both—Store all selected events in ePO - On-prem and SIEM databases. The default setting.

    Note

    You can use Select All and Deselect All, with Only selected events to the server, to select or deselect the all event checkboxes.

These settings do not take effect until the next agent-server communication.

The server accepts

Specifies, globally, events accepted by the ePO - On-prem server. Options include:

  • Events from any source — All events sent by any agent are process by the ePO - On-prem server. The default setting.

  • Events that were generated by the sending agent — The ePO - On-prem server processes only those events sent by the source agent.