filtering items which no need
Posted: Mon Aug 17, 2015 9:28 pm
how can i filter or delete log items which i am not sure i don't want to put on elasticsearch server.
for example, the following program
\device\harddiskvolume2\program files (x86)\nxlog\nxlog.exe
The Windows Filtering Platform has permitted a connection.
Application Information:
Process ID: 1076
Application Name: \device\harddiskvolume2\program files (x86)\nxlog\nxlog.exe
Network Information:
Direction: Outbound
Source Address: 192.168.1.1
Source Port: 49157
Destination Address: 192.168.1.2
Destination Port: 3515
Protocol: 6
Filter Information:
Filter Run-Time ID: 71242
Layer Name: Connect
Layer Run-Time ID: 48
for example, the following program
\device\harddiskvolume2\program files (x86)\nxlog\nxlog.exe
The Windows Filtering Platform has permitted a connection.
Application Information:
Process ID: 1076
Application Name: \device\harddiskvolume2\program files (x86)\nxlog\nxlog.exe
Network Information:
Direction: Outbound
Source Address: 192.168.1.1
Source Port: 49157
Destination Address: 192.168.1.2
Destination Port: 3515
Protocol: 6
Filter Information:
Filter Run-Time ID: 71242
Layer Name: Connect
Layer Run-Time ID: 48