Help Document

Log Collection Filters

In this page:

Overview

Log Collection Filters in Log360 Cloud allow admins to control and streamline the log ingestion process by specifying which logs should be collected or excluded based on log source, log format, and custom-defined conditions. You can create filters for both device groups and cloud sources. This ensures that only relevant and necessary log data is processed, stored, and analyzed.

Filters support logical operators like AND and OR, allowing you to combine multiple criteria.

This page explains how to create, configure, and manage Log Collection Filters to help optimize storage usage, improve processing efficiency, and retain actionable, security-relevant data.

Creating a Log Collection Filter

  1. Log in to your Log360 Cloud account.
  2. Go to the Settings tab and select Admin.
  3. In the left pane, navigate to Data Storage and click Log Collection Filters
  4. Log Collection Filter

    Figure 1: Navigating to Log Collection Filters

  5. Click + Add New Filter in the top right corner.
  6. Log Collection Filter

    Figure 2: Adding a new filter

  7. Enter a unique name for the filter in the Filter Name field.
  8. Log Collection Filter

    Figure 3: Configuring a log collection filter

  9. In the Select Log Format drop-down menu, choose the appropriate log format.
  10. NOTE: Cloud sources can also be selected from the Log Format drop-down.
  11. Click the icon-add icon to select Log Sources.
  12. In the pop-up window, select the desired device groups or Cloud Sources. You can also use the Search Elements bar to locate specific sources.
  13. Log Collection Filter

    Figure 4: Selecting a log source

  14. Click OK to confirm your selection.
  15. Using Filter Criteria, you can define the conditions that determine which logs should be collected or excluded. Choose one of the following options:
    • Exclude: Omit logs that match the specified criteria.
    • Collect Only: Include only logs that match the specified criteria.
    NOTE: A filter can be configured to perform only one action, either Exclude or Collect Only. To apply both actions for the same set of devices or log sources, you must create two separate filters: one for exclusion and another for inclusion.
  16. Log Collection Filter

    Figure 5: Configuring a log collection filter

  17. Click the icon-add icon to add additional filter criteria. You can combine multiple conditions using logical operators:
    • AND means all conditions in the group must be true for a log to match.
    • OR means at least one condition in the group must be true for a log to match.
  18. Log Collection Filter

    Figure 6: Adding additional filter criteria

  19. To create advanced filters, click + Add Group to define multiple groups of conditions. Each group can be configured with its own set of criteria and logical operators.
  20. Log Collection Filter

    Figure 7: Adding a group

  21. Click Add to save the configurations.

Managing Log Collection Filters

To enable or disable a log collection filter:

  1. In the Log Collection Filter page, select a filter from the list.
  2. Click the icon-disable icon to disable the filter.
  3. Log Collection Filter

    Figure 8: Disabling a log collection filter

  4. To enable a filter, select a disabled filter and click the icon-enable icon
  5. Log Collection Filter

    Figure 9: Enabling a log collection filter

To delete a filter:

  1. Select the filter you want to remove.
  2. Click the icon-delete icon.
  3. Log Collection Filter

    Figure 10: Deleting a log collection filter

  4. A confirmation pop-up will appear. Click Yes to confirm and permanently delete the filter.
NOTE: Predefined filters cannot be deleted.

Log Collection Filter

Figure 11: Confirming deletion of the log collection filter

To search for a filter:

  1. Click the Search icon at the top-left corner of the filter table.
  2. Enter the filter name in the search bar.
  3. Log Collection Filter

    Figure 12: Searching for a filter

  4. The table will automatically update to display filters that match the entered keyword.

To export a filter:

  • Select the filter you want to export.
  • Click the icon-option icon and choose Export.
  • Log Collection Filter

    Figure 13: Exporting a filter

  • The selected filter will be downloaded as an XML file.

To import filters:

  • Click theicon and select Import.
  • In the Import Filter Profile(s) pop-up, browse and select the XML file containing the filter profile.
  • Log Collection Filter

    Figure 14: Importing a filter

  • Click Import to upload and apply it.

To edit an existing filter:

  1. Click the icon-edit icon next to the filter you want to update.
  2. Log Collection Filter

    Figure 15: Editing a filter

  3. You can modify the Filter Name, Log Sources, and Filter Criteria.
  4. NOTE: You cannot edit the filter criteria of predefined filters. However, you can modify the associated device(s) or device group(s) in predefined filters.

    Log Collection Filter

    Figure 16: Editing a filter

  5. Click Update to save the changes.