Sorry, but with all due respect, That's not a solution, it's a "work around" for something that's not right.
I don't have time to every time I want to see certain things in logs do an export, pull into Excel and sort. That's the job of the built-in logging and reporting. I'd be exporting several times a day in some cases.
Since the days of SAV, SEP has had almost worthless alerting and reporting and I'm not the only one saying that. SEP reports seem to me to be made for those management types who are clueless about details but love pretty pie charts. I want a report that's got meat and potatos.
I should be able to hit that monitors tab any time of the day, several times a day if necessary, and filter the logs to show me a list of items I'm looking for. Part of the reason we remain virus free for over 28 months is also because we monitor - we see what folks are up to. We've got to monitor logs and try to check reports because the SEP alerting is also worthless and broken. The product does protect (with proper configuration) but it really doesn't tell you much else without jumping through hoops.
I need to several times a day take a quick look at what's going on. Our people click anything that looks cool or appears to be a link - apparently fearing they might miss out on something, I dunno, but it's like having to watch over beginners, so the logging and reporting is at least as useful as any other tool could be, however, in the case of SEP, it's missing so many obvious things that are available in other products. If it wasn't for the great protection, the reporting, logging and ALERTING sure couldn't stand on its own. The alterting is worthless, the Monitors/logs is nearly so at times, especially without the ability to filter to the negative - to EXclude things or give it multiple criteria. It's all or 1.
I'd also add - you get all or 1 for severity level - and yet OTHER PRODUCTS allow "warning or above" for example. Not SEP - it's either critical, OR major, OR minor, OR informational. Why not "major and above"?? Seriously, we've got a number of other products that handle logs that allow that sort of filtering. They give us choices. They don't put us in a box and say "here's the reports any way you like them, as long as you like them like we do". That's the Henry Ford method - any color you want as long as it's black. SEP is "any report you want as long as it's one of our own standard favorites"