Filters in Unified Events
The unified events table initially displays multiple types of firewall events from the past hour. You can filter the default view of unified events for a more granular contextual picture of activity on your network. Filters support exclusion as well as inclusion filter criteria.
Filters help you to provide quick access to critical information. For example, if you are a firewall administrator and you want to allow or deny specific application access to some users, you can set user search criteria to scan through the firewall logs. The event viewer displays event logs that match the search criteria.
Procedure
Step 1 | Choose . | ||
Step 2 | Enter the filter criteria:
| ||
Step 3 | Perform the search.
Events in the unified events table are not aggregated when the displayed columns all hold identical values. Every event matching your filter criteria is listed individually. |
What to do next
To save a custom filter, see Save a Search in Unified Events topic.