Extracting alerts from the database

I have searched both the forum and the web for any way that I could extract alerts from the Glasswire database
I have had over 500 “Internet access changed” alerts since last August and have not been successful finding the cause and have been keeping an Excel spreadsheet of those alerts. It would be nice to have a Glasswire offshoot that did not connect to the Internet that could edit the database (archived) and archive portions of the database (or if Glasswire could be deactivated and turned into a database editor and then be activated again).
I’m certain there are all sorts of issues with such a tool, but the alerts are one of the data that I have studied to try to nail this problem and the quantity of data is overwhelming.
It would equivalently be helpful if there were a description about how each alert is raised (Win 10 event,…?)

It would also be nice if there were a way to delete all of the “While you were away…” alerts where 0 apps accessed the network; they take up about half of the alert portion of the database. When I noticed how many such alerts were posted I turned off the alert even though the information about what WAS running while I was away would be nice to have.

I did read the thread in the Glasswire Help category that kind of addressed this issue, but I thought maybe here might be a better place to put it.

2 Likes

@MikeLainhart

Thank you for your feedback on extracting our alerts from GlassWire.

We do have a new setting that might help you. Go to our top left menu and choose “settings” then look for “Send GlassWire Alerts to Windows Event Log”. If you check this our alerts are also sent to the Windows Event Log, and I believe the Windows Event Log has many different options for extraction.

Unfortunately though I don’t believe this will send your old alerts there, only new ones going forward.

1 Like

I retired in 2003 from a real fun career developing software and occasionally managing a small network - it is still fun to try understanding what is going on in my personal little computer world.
That is kind off an excuse for why I have updated Glasswire with less than careful understanding of what is new in the update.
AND, posting the Glasswire alerts to the Event log will be helpful - in the future. I am looking forward to the time when I have my frequent Internet interruptions alleviated so that I can “clear” the history which will be an adequate way of getting rid of the alerts that were of little use to me.
BUT, I’m a little frightened to hit the “Clear” control because I don’t know if I will have the option of archiving the current database. I do see that there are some archived backup databases (not sure where they came from - I didn’t save them) and I have seen some postings about how to open glasswire with those databases - I would feel more comfortable if there was a “Save Database As” and “Load Archived Database” option available - I see there are some old postings requesting that but nothing that specifically says that such an options are not possible. Probably a bad idea to have Glasswire “active” when examining an archived database and it looks like “Deactivate”/“Activate” Glasswire may be an economic option not an operational option.

(By the way: I did turn on the alerts to event logs mostly to see where they were being logged and did see a few “First Network activity” alerts posted but I did not see the alert for Things Monitor turned on. Should ALL alerts be sent to the event logs? If not which ones are not?)

Thanks, Mike

@MikeLainhart

I believe all alerts should be sent to the event logs. If you’re seeing some don’t please be 100% sure they happened before you switched this setting on and I’ll ask our team to try to reproduce this. Sorry for the issue.

Here is how to back up different parts of GlassWire, just in case.
https://www.glasswire.com/userguide/#Backup_Settings

Thanks for your feedback! We’re looking at a more simple backup option.

I don’t know if the settings changes count as “alerts”; they do show up in the alerts tab:


The Things monitor turned on at 10:04AM - did not show up in event log at 1:42PM

1 Like

By the way, the restore instructions for the database if the location has been changed, step 2 and 3 I suspect should refer to the locations on the D: drive.

1 Like

For the alerts we discussed this with our team. We purposely don’t show alerts that show changes to settings because we thought admins would find these alerts annoying, since they just show alerts settings changes.

We’ll continue to discuss if we should make changes in the future, thanks for your feedback.

I’ll share the database instructions with our webmaster, thanks!

Hmm? Seems to me that posting a settings change is an easy way to avoid questions about about “what happened that I never saw that alert before” or thinking that alerts mean that a problem has been fixed when the alert has just been turned off.

1 Like

Thanks for your feedback. Our team will discuss and decide what to do with future updates.