---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Filter the events that an event rule applies to

# Filter the events that an event rule applies to {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Define a filter to restrict to which events the event rule must apply. Configure the
filter by providing a set of conditions that each event must match to be either excluded or
included from applying to the event rule.

## Before you begin

Ensure that a name is specified for the event rule.

Role required:
evt_mgmt_admin

## About this task

To construct the required condition statement, you can use event fields as well as additional fields that are defined in the Additional Information field of the event. Use these fields to configure conditions that can exclude events. Alternatively, you can filter incoming events to ensure that only those events that meet the required conditions are included.  
Note:  
Event rules filter is case-sensitive.

While working in the Event Filter tab:

* In the Event rule list, if you selected a recommended rule or an existing rule, the filter fields are populated with values from these events. You can use these filter fields to compose filter conditions.
* You can click another tab (for example, Threshold), work in that area and then return to work in the Event Filter area without losing information.
* Use the right-panel as a source of reference for which fields are available to be used when composing filter conditions.

{#t_EMCreateFilter__ul_s2k_ygp_ry}  
Note:  
Event filters created on additional_info fields only perform a string comparison and not a numeric comparison, even if the information entered into the value field appears as if it is numeric, as depicted in the following graphic:  
![Event filter string comparison]()  

## Procedure

1. Navigate to AllEvent ManagementRulesEvent Rules.
2. Click New or open an event rule.
3. Click Event Filter.  
4. To ignore events, select Ignore events that match this filter.  
   All events that match this event rule are ignored. You can add more conditions to the filter by clicking either OR or AND.  
   Note:  
   Even if an event is ignored by an event rule, the event is still recorded in the Event \[em_event\] table. Select this option to inhibit an alert from being created and be associated with the event. {#t_EMCreateFilter__step_np3_jsh_hz}
{#t_EMCreateFilter__step_np3_jsh_hz}
5. To configure conditions to which the event rule must apply, click New Criteria.  
   You can add further conditions by clicking either OR or AND.  
   Note:  
   The % character is not supported in filter conditions. {#t_EMCreateFilter__step_sp3_jsh_hz}
{#t_EMCreateFilter__step_sp3_jsh_hz}
6. You can add field names to the Event Rule Simple Field Black Lists \[em_event_rule_black_list\] table to either show or hide fields from the filter.  
   * To remove fields from the filter and the right panel, add a new black list field with Show in rule not selected.
   * To remove fields only from the filter and still enable it to appear in the right panel, add an exclusion list field with Show in rule selected.
   {#t_EMCreateFilter__ul_pl4_kc2_sy} {#t_EMCreateFilter__step_up3_jsh_hz}
{#t_EMCreateFilter__step_up3_jsh_hz}
7. Click either Save or Submit. {#t_EMCreateFilter__step_xp3_jsh_hz}
{#t_EMCreateFilter__step_xp3_jsh_hz}{#t_EMCreateFilter__steps_yp3_jsh_hz}

## Example

Example showing filter conditions that are specified to run a rule when the metric name starts with the word "disk". For this example, any resource is acceptable, as long as it is not "cpu" and the node name is "MyServer".

Example to filter events using time conditions. In the Select Field or add New field, select <kbd class="ph userinput">Time of event</kbd>.
Specify the required time conditions, for example, anytime after yesterday.

**Related concepts**   

* [Use event input information](https://servicenow-prod.fluidtopics.net/Xf_3GkyF5V1e21XESUXm9A "The Event Input pane that is included in the steps to create an event rule provides a reference to the information that you can use when configuring an event rule.")  
**Related tasks**   

* [Create or edit an event rule](https://servicenow-prod.fluidtopics.net/S0ulPjfvh7Pz7phgkfVYFw "You can create event rules to generate alerts for tracking and remediation. Use team-based integrations in event rules to make sure that connector ownership and execution of rules give precedence to general rules. Teams can maintain consistency and hierarchy while offering flexibility and customization options.")
* [Configure an event rule to customize alert content](https://servicenow-prod.fluidtopics.net/y3wetDYMwXph7QgT~DFEhg "You can configure an event rule to customize alert content. You can customize the order of the fields and select which fields display. The fields in the left-hand work area of the Transform and Compose Alert Output section of an event rule are the fields that appear in the generated alert.")
* [Set a threshold to suppress alert generation](https://servicenow-prod.fluidtopics.net/hz5gPG5ZhuIhZeKZaBd7gA "The event threshold is the rate upon which Event Management generates an alert. Receiving multiple events for a device over a short interval may warrant creating an alert, as the condition may be serious. However, receiving events over a longer interval may indicate a less serious situation which would not warrant creating an alert.")

*[\>]: and then


