In the console tree of ISA Server Management, click
Monitoring.
In the details pane, click the Logging tab.
On the Tasks tab, click Edit Filter.
In Filter by, select one of the log fields.
In Condition and Value, specify the appropriate
condition, and then click Add To List.
Repeat steps 4 and 5 to add more conditions to the filter.
Then, click Start Query.
Notes
To open ISA Server Management, click Start, point to
All Programs, point to Microsoft ISA Server, and then
click ISA Server Management.
For ISA Server 2006 Enterprise Edition, expand
Microsoft Internet Security and Acceleration
Server 2006, expand Arrays, expand
Array_Name, and then click Monitoring.
For ISA Server 2006 Standard Edition, expand Microsoft
Internet Security and Acceleration Server 2006, expand
Server_Name, and then click Monitoring.
Important
The log viewer displays log data only if it matches all the
expressions included in the filter. The filter expressions are
combined using the logical AND operator.
To edit an expression in the filter list, click Edit
Filter. Then, select the condition and click
Update.
To delete an expression from the filter list, select the
applicable expression in Show only entries that match these
conditions, and then click Remove.
When you create the filter, you must specify exactly one Log
Time and one Log Record Type.
The log viewer updates data only when the Microsoft Firewall
service is running. When the Firewall service is not running, ISA
Server enforces lockdown mode. For more information, see Lockdown mode.
The log viewer can display information only about the Firewall
and Web Proxy logs.