Event Type Tab
The Event Type tab lets you define the objects and events that Threat Prevention monitors or blocks.

Each event type represents what the policy monitors or blocks. Use event filters to narrow or broaden the scope of monitoring or blocking. Click Add (+) to open the Event Selection window. Your licensed modules determine what event types are available. Event types that aren't available or licensed appear grayed out in the Event Selection window. See the License Manager Window topic for information.
Event Selection Window

Check the box for the event type you want and click OK. The corresponding event filters show at the bottom of the Event Type tab. You can assign multiple event types to a policy.
Create different policies for different event types for reporting purposes. Otherwise, one report will have a mix of different types of data. There are a few exceptions to this feature.
After you select the event type to monitor, use the filters to scope the policy.
Each filter tab acts like an "AND" statement for the filter. Any empty filter tab functions like an "ALL" for that filter set.
Save all changes made to a policy or a template before leaving the configuration interface.
See the following topics for additional details:
- Active Directory Changes Event Type
- Active Directory Lockdown Event Type
- Active Directory Read Monitoring Event Type
- AD Replication Monitoring Event Type
- AD Replication Lockdown Event Type
- Authentication Monitoring Event Type
- Authentication Lockdown Event Type
- Effective Group Membership Event Type
- Exchange Changes Event Type
- Exchange Lockdown Event Type
- File System Changes Event Type
- File System Lockdown Event Type
- File System Enterprise Auditor Event Type
- FSMO Role Monitoring Event Type
- GPO Setting Changes Event Type
- GPO Setting Lockdown Event Type
- Process Guardian – Monitor Event Type
- Process Guardian – Protect Event Type
- Password Enforcement Event Type
- LDAP Monitoring Event Type
- LDAP Lockdown Event Type
- LDAP Bind Monitoring Event Type
- ADCS Monitoring Event Type
- ADCS Lockdown Event Type
Event Filters Overview
Policies are scoped using Event Filters tabs that correspond to the event type you select in the Event Selection window.
The filters appear on the Event Type tab when an event type is selected.
Several filters let you set both an Include and Exclude list. The Exclude list takes precedence over the Include list. When an event contains an item from both lists, the system excludes it.
When using a Lockdown Event Type, choose Block or Allow for the filter.
- Block – Blocks all items in the list, or if the list is empty, blocks all items for that filter category
- Allow – Allows only items in the list and blocks all others. If the list is empty, allows all items for that filter category.