Event Filters determine which collected SQL events should be kept for processing by the Collection Server. Same as your audit settings, the Event Filters should correlate with the events you need to track on the SQL server in order to meet your compliance objectives.
After receiving the trace files from the SQL Compliance Manager Agent, the Collection Server applies your Event Filters. Any matching events are permanently deleted and eliminated from the data stream. All remaining events are processed for alerts and stored in the appropriate Repository database.
When enabling Sensitive Column auditing on a table, the Collection Server preserves all SELECT and DML events associated with the audited columns even though you may have created an event filter to exclude SELECT and/or DML events. Therefore, when using an Event Filter for a specific Login, all events captured get filtered except for the Sensitive Column SELECT and/or DML operations.