Submit a ticketCall us

AnnouncementsTHWACKcamp 2018 is here

2018 is the seventh year for THWACKcamp™, and once again we’ll be live October 17 – 18 with packed session tracks covering everything from network monitoring and management, to change control, application management, storage, cloud and DevOps, security, automation, virtualization, mapping, logging, and more.

Register for online sessions.

Home > Success Center > Log & Event Manager (LEM) > LEM - Knowledgebase Articles > How to Create a Filter to Display FIM Data

How to Create a Filter to Display FIM Data

Table of contents
Created by Erica Gill, last modified by MindTouch on Jun 23, 2016

Views: 1,341 Votes: 0 Revisions: 4

Overview

This article describes how to build a filter to display data collected by FIM events.

Environment

  • LEM 6.1
  • LEM 6.2

Steps

  1. In the LEM Console, go to Monitor.
  2. Click the + icon on the upper left hand corner of the screen to add a New Filter.
  3. In the Filter Configuration window, add a filter name and using drag and drop across the appropriate filters to the Condition pane.
    • For example, to filter for read events from a FIM connector for one particular file on one particular server use:
      • FileRead.DetectionIP =<IPAddressofMonitoredHost>
      • FileRead.ToolAlias=<ConnectorName>
      • FileRead.FileName=<FullPathofFile>
    • For example,
      • FileRead.DetectionIP =10.10.4.125
      • FileRead.ToolAlias=FIM File and Directory
      • FileRead.FileName=G:\SolarWinds\Area51\RestrictedFile.txt

Note: When working with filters an iterative approach, building a general filter and then narrowing down the filter based on the events filter can be the best way to narrow down to very specific events.

Last modified

Tags

Classifications

Public