- Using the Events Browser to identify fields
- Create the custom rule
- Changing the order of processing rules
Using the Events Browser to identify fields
The GFI Events Browser enables you to view all events which have been captured by GFI EventsManager. This tool is useful to gather further information on each event processed and provides the information required to create your custom processing rules.
- The Events Browser can be found in the GFI EventsManager Management Console
- Locate the event you wish to create a custom processing rule for.
- In the Events Browser, you can view the details of the particular event such as the Event ID and also additional field information included in some events. For the purpose of this article, a custom rule will be created to gather Event ID 592 and when a new Microsoft Management Console (mmc.exe) process is started.
Create the custom rule
- Within the GFI EventsManager Management Console, click on the 'Configuration' button and select 'Event Processing Rules'
- Create a new folder to store your custom rules by clicking on the 'Create Folder' link under the 'Common Tasks:' section
- Add the name for the folder such as 'Custom Rules'
- Click on the 'Create new rule set...' link under the 'Common Tasks:' section and give it a name. Example 'Detailed Tracking'
- To create the new rule click on the 'Create new rule...' link
- Specify a name for the new rule, such as 'mmc.exe process created', and enter a brief description. Click on the 'Next' button to proceed
- Select which type of event log(s) will apply to this rule. For this demonstration Windows Security Event logs is selected. Click on the 'Next' button to continue
Enter what type of filtering conditions are applied for this rule. In this demonstration, Event ID 592 will be entered. If you wish to perform advanced filters, click on the 'Advanced...' button and enter any additional filters by clicking on the 'Add...' button. In this example, the following Filter Restrictions were also added:
Field Name: Field 2
Select Field Operator: Contains the text
Enter Field Value: mmc.exe
- Click on 'Next' to proceed through the wizard
- Define the occurrence and importance of the rule and click on 'Next'
- Specify what actions need to be taken when this rule is triggered and click 'Next'
- Click on 'Finish' to create the rule
Changing the order of processing rules
When an event is collected in GFI EventsManager, the rules are processed from top the bottom. If you wish for your new custom event processing rules to have a higher priority within the Events Processing Rules list, perform the following procedure:
- Click on the newly created custom rules folder
While holding the CTRL key, press the Upward arrow key on your keyboard to increase priority (downward arrow key will reduce priority)
Note: This can also be done by right clicking on the folder and select increase/decrease priority
Finally, we need to assign the new custom rules for processing in our Event Sources. This can be done by performing the following procedure:
- In the GFI EventsManager Management Console, click on 'Configuration' and select 'Event Sources'
- Right click on the Event Sources Group you wish to assign this new processing rule and select 'Properties'
- Under the 'Windows Event Log' tab, ensure that the new processing rule is selected and enabled
- Click on the 'OK' button to save changes