Skip to content

Filter Management

Managing and Testing Subscription Filters

Subscription filters define which events are forwarded to a central server, and their accuracy is critical for effective event monitoring. This section covers how to edit, prioritize, and validate subscription filters to ensure they operate as intended.


Editing Subscription Filters

To modify an existing subscription filter, use PowerShell to adjust its criteria or priority. Filters are defined as part of an event subscription, which can be edited using the Set-EventForwardingSubscription cmdlet.

Adjusting Filter Criteria

Use the Get-EventForwardingSubscription cmdlet to retrieve the subscription, then update its filter parameters:

# Retrieve the subscription
$subscription = Get-EventForwardingSubscription -Name "MySubscription"

# Update filter criteria (e.g., event ID 123)
$subscription.FilterHashtable = @{
    LogName = "Security"
    ID = 123
}

# Apply changes
Set-EventForwardingSubscription -InputObject $subscription

Prioritizing Filters

When multiple subscriptions apply to the same event, priority determines which subscription takes precedence. Lower numerical values indicate higher priority:

# Set priority for a subscription (e.g., priority 1)
$subscription.Priority = 1
Set-EventForwardingSubscription -InputObject $subscription

Note: Priority is only effective if subscriptions are configured to use the same event source.


Testing Subscription Filters

Validation ensures filters select events correctly. Use the following methods to test:

1. Generate Test Events

Trigger events that should match your filter criteria. For example, log an event manually:

# Log a test event (requires administrative privileges)
Write-EventLog -LogName "Application" -Source "TestSource" -EventID 42 -Message "Test event for filtering"

Check if the event appears in the central server’s event log or is forwarded as expected.

2. Use Test-EventForwarding

Validate filter syntax and configuration:

Test-EventForwarding -SubscriptionName "MySubscription" -EventID 42

This cmdlet simulates event forwarding and reports errors in the filter definition.

3. Monitor Event Logs

Check the Event Viewer on the central server for forwarded events. Look for entries under:
- Applications and Services Logs > Microsoft > Windows > EventForward > Operational


Troubleshooting Common Issues

  • Incorrect Filtering: Verify FilterHashtable syntax matches event properties (e.g., LogName, ID, Level).
  • Priority Conflicts: Ensure subscriptions with overlapping criteria have distinct priorities.
  • Permissions: Ensure the subscription has the correct ForwardingServer and Collector permissions.

Key takeaways

  • Use Set-EventForwardingSubscription to edit filter criteria and adjust priority.
  • Test filters with Test-EventForwarding and manual event generation to validate accuracy.
  • Prioritize subscriptions numerically (lower values = higher priority) to resolve conflicts.
  • Monitor the central server’s event logs to confirm events are forwarded as expected.
  • Validate filter syntax to avoid errors in event selection.