Hi All
I use agent manager to collect windows events. but I find much events almost relates windows firewall and filter plateform events...
These events are non-essential for managers...
If the manager wants to filter these events, my impression is to add a Filter to the event source object like below screenshot
But I found that the settings I added didn't seem to work...These events still send to sentinel message bus , and could been search from web console
How can I "surely" let the Event Source filter these events that contain certain characters been drop to decrease EPS??
or How could I do from agent manager to not collect these events ?
Thanks!!
Wencheng