Prioritizing Custom Rules
The Custom Rules are prioritized in the order as they are displayed (from highest on the top) in the Custom Rules list.
The priority of rule determines the Retention rule that is applied to which log source. You can change the priority of custom rules by moving them up or down in the Custom Rules list.
To view the Retention rule that is applied to a device or group, click the View All Rules button. The screen displays the Effective Rule for every device and device group. The Effective Rule Name column displays the Rule that is in effect after considering rule prioritization.
Example
- We created two Custom Retention Rules named RR1Week and RR3Months that have Raw Data Retention period of 1 Week and 3 Months respectively.
- Then the device group named Windows Machines is assigned to the RR1Week retention rule.
- Similarly, a log source named FrontDesk1 is assigned to the RR3Months retention rule.
- Since FrontDesk1 is assigned to the RR3Months retention rule with a retention time of 3 Months and is also a part of the group Windows Machines with a retention time of 1 Week, to decide the Effective Retention Rule (i.e. the retention time applicable to the data received from FrontDesk1) the system will use the data retention rule priorities. If the rule RR1Week is prioritized higher, then the Effective rule for FrontDesk1 will be RR1Week.
- However, if the rule RR3Months is prioritized higher, then the Effective rule for FrontDesk1 will be RR3Months.
Procedure
Copyright © Cloud Software Group, Inc. All rights reserved.