Free Trial

Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.


Share this Page URL
Help

Chapter 15: Event Processing Rules > Frequently Asked Questions - Pg. 379

EventProcessingRules·Chapter15 379 Frequently Asked Questions Q: How many events can GFI EventsManager process? A: It really depends on your hardware's capabilities, but the GFI Web site claims that the software can process over six million events per hour. Q: Is there any way to disable the default alerting? A: By default, the alerting occurs because messages fall into a particular classification. If you want to disable alerting, you should modify the default classifications. Q: Will creating an excessive number of rules bog down the server? A: It seems theoretically possible, although my lab server never bogged down except when I was generating an excessive number of log entries. Q: What are noise reduction rules? A: Windows creates some event log entries that are practically meaningless. Noise reduction rules are typically designed to prevent these types of events from being archived in the database. This speeds up database access and helps conserve disk space.