2021-07-01 08:30 AM
Hi to all,
I am collecting windows log through NWE agent and I would like to configure a fiter to drop some specific collectio which are impacting a lot on my licence usage.
If i understand well, after have configured the windows log policy to forward the log to the VLC i will be able to configure an event source filter. If so, which type of collection should I configure? Syslog?
Thank you
Carmen
2021-07-03 01:47 AM
Hello.
If I uderstood right, you need:
Admin - Services - Log Collector - Config - Event Sources -
drop down menu - Windows; from nearby drop down menu select Filter.
But not sure that it works for NWE.
2021-07-07 03:04 AM - edited 2021-07-07 03:07 AM
Hello @MaximMarchenko,
yes, you got the point but, as you was suspecting, the filter configurable from Admin - Services - Log Collector - Config - Event Sources only work for WinRM collections.
For NWE it is possible to filter something through the Windows Log Policy but the low granularity of this filter does permit to filter a particular event id while my aim is to filter a particular event id for a specific TargetUser.
As the NWE method of transport is actually Syslog i was hopping to get the solution in the syslog collection filter but it didn't work
Thank you for the answer