I have downloadd the trial of Solarwinds SEM and have it up and running but struggling with the SQL auditing. I have configured the SQL auditing OK and it is passing data to the SEM (it is using the MS SQL connector). However, the server is in SEM and I can see the auditing events sometimes but what I want to do is create a filter in the filter groups so that I can just see the machine that I am auditing and just for that MSSQL connector. I am struggling a bit to find any of the correct filter options that would allow me to do this. Can anyone point me in the right direction?
I may as well ask at the same time, how would I set up a rule based on failed SQL logins (SQL auth) related to that connector? there doesnt seem to be any template for this