Filter out
Filter out event alerts based on matching event contents using regex or string pattern search.
I.E. User A is an automated user.
It logs on every 10 mins to computer A.
I want to exclude User A Logins from the sign in or sign out event 4624 or 4625
but I want to log every other user logon
Another example.
Filter out computer logon to domain by filtering out "\S+(.\$)"
1
vote
