Global filters are classified as Public Filters. Global filters are processed at the Collector Manager sequentially for each event until a match is found. Global filter evaluation stops for that event and the matched global filter action is taken for that event. The order of evaluation of global filters is top to bottom, as shown in the Console. They can be enabled or disabled as needed.
Global filters do the following:
Enable a global action on events, such dropping events, routing events to the database only or routing events to the database and the Sentinel Control Center or Routing events only to GUI or Sentinel Control Center
Are processed by Collector Manager
Are configured in the Admin tab under the Global Filter Configuration option where they can be enabled and disabled
Drop events
Can route events to the database only
Can route events to the database and to the Sentinel Control Center
Can route events only to Sentinel Control Center
Through the Global Configuration window, you can:
"Create Global Filter"
"Rearrange a Global Filter"
"Delete a Global Filter"
To Create a Global Filter:
Click the Admin tab.
Click Admin > Global Filter Configuration or select Global Filter Configuration in the navigation tree.
In the Global Configuration window, click Add.
In the new blank row, click Filter Name column.
Select a filter and click Select or Add (if you need to create a filter).
In the Active column, click Active box.
In the Action column, select the action that the global filter will have on events that pass this global filter. If an event does not meet any of the active global filters, then the default action determines how the event is handled.
You can set the Default Action box to one of the following:
drop: Events will not go to the Sentinel Control Center or the Sentinel Server database
database: Events will be sent directly to the database, bypassing the Sentinel Control Center
database and gui: Events will be sent to the Sentinel Control Center and Sentinel Server database
gui only: Events will be sent to the Sentinel Control Center.
Continue adding filters until you are finished.
Click Save.
To Rearrange Global Filters:
In the Global Configuration window, Select a filter and click Up or Down to move it to a different location on the list.
Click Save.
NOTE: When deleting a Global Filter, you will not get a confirmation message.
To delete a global filter:
In the Global Configuration window, Select a filter from the list and click Delete.
Click Save.