Modify configuration rules using Event Viewer

The Event Viewer runs in a separate window to the Application Control console. This enables users to drag (or copy and paste) items from Event Viewer to the console and immediately modify or create the rules required.

Events listed can be dragged and dropped or copied and pasted to create File Path, File Name, Folder or File Hash Rule Items for the following:

  • Rule Collections

  • Rule Sets > Executable Control > Allowed/Denied

  • Rule Sets > Privilege Management > Applications/Self-Elevation

Using query results to modify configuration rules

  1. Run a query in Event Viewer.

  2. Open the Application Control console.

  3. In the Configuration navigation pane, expand Rules and select the configuration rule required.

  4. In the Event Viewer dialog, select the event required and either copy or drag the item to the configuration dialog.

    You can select and add multiple events.

  5. Select the required rule type from the Select Rule Item Type dialog.

    • File Path: Copies the full path of the file from the event ID. Applies to file rules.

    • File name: Copies the file name from the event ID. Applies to file rules.

    • Folder: Copies the folder name and path from the event ID. Applies to folder rules.

    • File Hash: Copies the file hash from the event ID. Applies to signature rules.

  6. The rule item is added to the configuration immediately.

If the item added is a file or folder you can view and edit its properties and metadata to ensure integrity. Double-click the newly added item to open the Edit dialog, or right-click the item and select Edit.

By default, metadata is not enabled for items added via Event Viewer. Select the Metadata tab in the Edit dialog and select the checkbox(es) for the data required. The relevant data is displayed immediately. For further information, refer to Metadata.

Related topics

 Auditing

Management Center Help