XYGATE Merged Audit Reference Manual

Table Of Contents
XYPRO Technology Corporation 191 Proprietary and Confidential
Appendix D: Sample Filters
This Appendix provides some typical Filters.
D1: Filter out $CMONs I’m Alive Messages
Because $CMON runs in the background, it periodically writes a message to its audit.
Users frequently filter this message out of the XMA database. What makes these audit
events unique is the OPERATION, so that is the only DATA selection criteria required.
Example 1:
FILTERDEFBEGIN $IGNORE.XCM.ALIVE
STATUS ACTIVE
MOVER_BEGIN
MOVER_SELECT_BEGIN
PRODUCT = XYGATECM
MOVER_SELECT_END
MOVER_END
DATA_BEGIN
DATA_SELECT_BEGIN
FILTERTYPE STRINGFILTER
AUDIT.OPERATION = ALIVE
DATA_SELECT_END
DATA_END
ACTIONCOLL_BEGIN
ACTION_BEGIN
ACTIONTYPE IGNORE
ACTION_END
ACTIONCOLL_END
FILTERDEFEND