Indicator Set exceptions are modifications of the Indicator Set that eliminate reports for actions that match the exception. They allow you to reduce or eliminate reporting of events that are not of interest, while leaving the rest of the Indicator Set functionality enabled.
To create an Indicator Set exception, you identify an ATI-related event on the Events page to remove from future reporting. You can create an exception specific to that event automatically, or you can modify the exception so that applies to a broader or narrower range of targets, processes, or users.
Indicator Set exceptions are specific to the Indicator Set that generated the event that you use to create them. You can create multiple exceptions at one time, but you cannot create an exception using a non-ATI-based event.
You can edit an Indicator Set exception after it is created (including its name), or you can add special parameters at the time of creation by create an advanced Indicator Set exception. However, an advanced Indicator Set exception can only be created for one event at a time.
Create Indicator Set Exceptions
To create Indicator Set exceptions by using the default method, perform the following procedure.
Procedure
Results
Each exception created in this way uses the name of the Indicator Set plus incrementing digits (for example, the first exception to the Windows System Configuration set is named “Windows System Configuration Exception 1”).
Create an Advanced Indicator Set Exception
To create an advanced Indicator Set exception, perform the following procedure.
Procedure
Results
The new exception appears in the Exceptions panel of the Indicator Set Details page.