IEV Filters

[ LiB ]  

Anyone who has viewed event logs appreciates that this task can involve sorting through large amounts of data, much of which is irrelevant in the context of a specific event that you are interested in analyzing. IEV provides a filtering functionality that allows you to filter a view according to one of the following criteria:

  • Alarm severity

  • Source address

  • Destination address

  • Signature name

  • Sensor name

  • Time

  • Event status

The filter you create is either inclusive or exclusive. If you create an inclusive filter, the events defined in the filter are included in the view. Likewise, if you create an exclusive filter, events that match your criteria are not included in the view.

To edit an existing filter, right-click the filter from the Filters folder in the lower-left pane and choose Properties from the drop-down menu. To create a new filter, choose New, Filter from the File menu. Follow the dialog box instructions to establish the criteria for your new filter and click OK to save and apply your settings. You can choose your filter from the drop-down menu when creating or editing a view from the Views folder.

[ LiB ]  

CSIDS Exam Cram 2 (Exam 642-531)
CSIDS Exam Cram 2 (Exam 642-531)
Year: 2004
Pages: 213 © 2008-2017.
If you may any questions please contact us: