Security Compliance

Add additional conditions to a default filter in SEM

This article provides brief information and a sample scenario on the key components to observe when modifying your filter. Editing an already existing filter: Software Installation/Update When you want to have an extra "not equal to" condition, but the modified filter does not appear to work.

First published date

10/10/2018 3:05 PM

Last published date

10/10/2018 3:05 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).

This article provides brief information and a sample scenario on the key components to observe when modifying your filter. 

Editing an already existing filter: Software Installation/Update 

When you want to have an extra "not equal to" condition, but the modified filter does not appear to work.

For example:

Let's say you do not want to see any SoftwareUpdate events where the ToolAlias is equal to Vista Security.

You include this into the filter, but it does not appear to work. What's next?

Product section

Security Event Manager

Cause

The issue is caused by misconfiguration.

Resolution

SEM Flash console (versions 6.3-6.5)

Note: Pay attention to the Events and Fields that you are using.

In this example, we do not want to see any Software Update events with the Tool Alias equal to Vista Security.

For our first attempt, we tried the following:

This does not seem to work, however. 

A closer look:

  • We are using the event: SoftwareUpdate
  • Then, the field: ToolAlias
  • In the default condition, we already have SoftwareUpdate Event in its own group.       

Like below:

If this is the case, then we do not need to place the new condition in its own group. We should place it in the same group as the SoftwareUpdate since they both share the same event.

  1. Close (press the x) on the Group that has just the softwareupdate.toolalias not equals to Vista Security.
  2. Go back to the Events > SoftwareUpdate.
  3. Then to Fields : ToolAlias
  4. Then click on the ToolAlias and drag it over to the group section that just has SoftwareUpdate.
  5. Wait until you see a solid straight red line in the group, then drop the SoftwareUpdate.ToolAlias != Vista Security here.

     

In the end you will see the following:

-Conditions: -

Group: SoftwareInstall checkmark

Group: SoftwareUpdate checkmark & SoftwareUpdate.ToolAlias Not equal To Vista Security

-End of conditions-

Like the following:

Click Save. 

Check under the Monitor page, and this filter should be working.

SEM HTML5 console (versions 6.6 and newer).
In the SEM Events Console, edit the Software Installation/Update filter as shown below.

Learn more about editing filters in the SEM Events Console here