Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 21093

Re: Configure TCPTrafficAudit Event to exclude anything with "ProviderSID: Microsoft-Windows-Security-Auditing 5156"

$
0
0

I'm not 100% sure what you mean by configuring the event, but I have a couple ideas (and you can reply and let me know if I'm totally off).

 

One, you can always exclude stuff in Rules and Filters by clicking the operator to switch it from "equals" to "does not equal."

2013-12-26 14_03_38-SolarWinds Log and Event Manager Console.png

 

You can also use Policy to filter what you do and don't see in the Console, and what triggers rules.  Policy is powerful, so please be careful unchecking or checking everything.  You access policy from the Manage Appliances menu, and then clicking the gear next to the LEM.  You'll see a Policy option.

 

If you search for 5156, you'll get this:

2013-12-26 14_02_28-SolarWinds Log and Event Manager Console.png

You can uncheck those boxes to basically stop the LEM caring about that Provider SID in that Event Class.

 

We have some documents on using Policy to reduce Windows Platform Filtering noise: SolarWinds Knowledge Base :: Disabling Windows Filtering Platform Alerts Using Alert Distribution Policy That might serve as a guide for how to work with the policies.


Viewing all articles
Browse latest Browse all 21093

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>