Who rated this post

cancel
Showing results for 
Search instead for 
Did you mean: 
Amir_Senn
Employee
Employee

1. LogID 2000 is correlated events. This exclude the event logs from being considered as event candidate itself.

2. SmartEvent doesn't do enforcement of any kind unless you attach an automatic reactions to an event. Exclusion is preventing the matched resources from being considered event candidate. This is in use for example in an environment in which you get false positive from a server due to large quantity of requests.

Kind regards, Amir Senn

View solution in original post

(1)
Who rated this post