DEFAULT Filter Policy
When you install the Operations Sentinel Windows Agent, a default filter policy named DEFAULT is established. When a Windows system first communicates with Operations Sentinel, the DEFAULT filter policy is automatically assigned and enabled. You can modify the DEFAULT filter policy, but you cannot delete it.
The DEFAULT filter policy, as released, contains two event sources. The DEFAULT event source, described below, handles events not otherwise covered by the filter policy. The IMS Server event source handles state change events for Service Processors.
DEFAULT Event Source
All filter policies have an event source named DEFAULT. If an event is received from a source that is not otherwise covered by the filter policy, the event settings of the DEFAULT event source determine if the event is forwarded to Operations Sentinel.
You cannot delete the DEFAULT event source, but you can change its event settings.
The default event settings of the DEFAULT event source are
Error = All
Warning = All
Information = None
Success Audit = None
Failure Audit = None