I am running 6.2.0RC1. I have FIM running on a file server and pointing to one folder. I get a lot of events with NT Authority\System in it. One file opened creates 8 events. 5 of 8 are from NT\System
Because they dont tell me anything about who did what i am trying to filter it out. I have set this filter but still get them. I have tried SYSTEM with * and without
Any ideas?

