Start a conversation

Creating New Rules From Existing Events

Overview

You may need to create a custom processing rule to apply specific actions (e.g., ignore, archive, send alerts, etc.) to all events with the same Event ID.


 

Solution

  1. From Events Browser, locate the required event log, right-click on it and select Create rule from event.

    mceclip0.png

  2. Enter a name and description for the rule.
  3. Specify when this rule should be applied:
  4. Select the importance (classification) that will be assigned to the matching events:
    • Critical
    • High
    • Medium
    • Low
    • Noise

      mceclip1.png

  5. From the Event Logs tab, select the logs for which this rule will apply.

    mceclip2.png

  6. From the Conditions tab, you can configure additional restrictions for the rule, which is optional - the Event ID of the selected log event is already added as a condition. 
  7. From the Actions tab, select the action you want to apply to the events:
    • Ignore the event.
    • Use the default classification actions (which are applied to events depending on their importance).
      Note: Default classification actions can be reviewed and modified under Configuration > Options > Default classification actions.
    • Select a custom action profile.
      You can add a new one by selecting the <New actions profile> option.

      mceclip3.png 

      Then, configure the actions that will be applied to the events. 

      mceclip4.png

  8. From the Threshold tab, specify the number of times an event must be detected prior to triggering alerts and remedial actions. This helps to reduce false positive alerts caused by repeated events in your event logs.
  9. Click OK to save the rule.
  10. If you want your custom rule to override existing processing rules, make sure to increase its priority by right-clicking on the folder and selecting Increase Priority or pressing Ctrl+Up until the folder will be at the top of the list.

    mceclip0.png

 

 

Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. Priyanka Bhotika

  2. Posted 14 days ago
  3. Updated 14 days ago

Comments