SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

Simple Filters

Simple Filters enable users to append and order multiple include and exclude search criteria to a single list.

The following log types are supported:

Supported Log Types
Event Logs
Syslogs
Text, CSV and W3C Logs

In this Topic

How to Create Simple Filters

  • From the Menu Bar select File | New. The Create New Object View displays.
  • Select Filter. The New Filter view displays.
  • Use the Name text box to specify a unique name.
  • From the Type drop-down select the type of object to create the filter for.
  • From the Sub type drop-down select Simple. The Simple Filter View displays.
  • Use the Add Add Button button to add new criteria to the filter.
  • Use the Delete Delete Button button to delete the selected criteria.
  • Use the List List Button and Table Table Button toggle buttons to toggle view between a List View and a Table View.
  • Use the Order By Move to Top Button Up Button Drop-Down Button Move to Bottom Button buttons to change the order in which multiple criteria are applied.

Simple Event Log Filters

  • Use the Visibility drop-down to configure to either include or exclude entries that match this criteria.
  • Use the Levels Level Buttonstoggle buttons to include or exclude specific levels.
  • Use the Search Text text box to specify the message search criteria.
    • Optionally use the Match Case Match Case Button to match the case.
    • Optionally use the RegEx Regular Expressions Toggle Button to search using regular expressions.
  • Use the Sources text box to specify the Source to search for. Comma-separate multiple items.
  • Use the Categories text box to specify the Source to search for. Comma-separate multiple items.
  • Use the Event IDs text box to specify the Event IDs to search for. Comma-separate multiple items. Dash-separate Event ID ranges.
  • Use the Users text box to specify the User to search for. Comma-separate multiple items.
  • Use the Hosts text box to specify the Host to search for. Comma-separate multiple items.
  • Use the Logs text box to specify the Log to search for. Comma-separate multiple items.
  • Use the Enabled checkbox to disable criteria.

Simple Syslog Filters

  • Use the Visibility drop-down to configure to either include or exclude entries that match this criteria.
  • Use the Priority check boxes to include or exclude specific priorities.
  • Use the Search Text text box to specify the message search criteria.
    • Optionally use the Match Case Match Case Button button to match the case.
    • Optionally use the RegEx Regular Expressions Toggle Button button to search using regular expressions.
  • Use the Sources text box to specify the Source to search for. Comma-separate multiple items.
  • Use the Applications text box to specify the Application to search for (RFC5424). Comma-separate multiple items.
  • Use the Process IDs text box to specify the Process IDs to search for (RFC5424). Comma-separate multiple items.
  • Use the Message IDs text box to specify the Message IDs to search for (RFC5424). Comma-separate multiple items.
  • Use the Data text box to specify the Data to search for (RFC5424). Comma-separate multiple items.
  • Use the Hosts text box to specify the Host to search for. Comma-separate multiple items.
  • Use the Enabled checkbox to disable criteria.

Simple Text Log Filters

  • Use the Visibility drop-down to configure to either include or exclude entries that match this criteria.
  • Use the Search Text text box to specify the message search criteria.
    • Optionally use the Match Case Match Case Button button to match the case.
    • Optionally use the RegEx Regular Expressions Toggle Button button to search using regular expressions.
  • Use the Hosts text box to specify the Host to search for. Comma-separate multiple items.
  • Use the Logs text box to specify the Log to search for. Comma-separate multiple items.
  • Use the Enabled checkbox to disable criteria.

Sample Simple Event Log Filter

List View

Sample Simple Event Log Filter Criteria Displayed in a List

Table View

Sample Simple Event Log Filter Criteria Displayed in a Table

Related Topics

Complex Filters

Filters