Product manual
GFI EventsManager 6 Browsing Stored Events | 127
Note
To completely remove event logs from GFI EventsManager, you must run a Commit
Deletion job on the selected database. For more information refer to Commit deletions.
6.2.4 Searching stored events
Use the event finder tool to search and locate specific events using simple customizable filters. To
search for a particular event:
1. Click Events Browser > Actions > Find events.
Screenshot 90: Event finder tool
2. Configure the event search parameters through the options provided on top of the right pane. To
trigger a case sensitive search, click Options and select Match whole word.
3. Click Find to start searching.
6.2.5 Identifying rules using the rule finder tool
GFI EventsManager enables you to identify the event processing rule which triggered the selected
event log.
To identify the rule(s) used for a specific event:
1. From Events Browser, right-click an event log.
2. Click Find Rule. Doing so will take you to Configuration tab > Event Processing Rules. For more
information refer to Events Processing Rules.
6.3 Managing Events Browser views
Event logs are automatically categorized in different folders, according to the event log type and the
source from which it was generated. In GFI EventsManager, these folders are referred to as Views.
GFI EventsManager includes a comprehensive list of views that enable you to start categorizing
processed event logs upon installation. New views can be created and the existing ones can be
modified. The following sections provide with information about managing the Events Browser views:
Creating Root Views and Views
Editing a view
Deleting a view
6.3.1 Creating Root Views and Views
In Events Browser, GFI EventsManager enables you to create the two different types of views
described below: