Configures a rule to filter out all events that are sent from an Network Security appliance to Helix for a specified event type or for all event types.
For more information on configuring event filter rules, see the Network Security User Guide.
The following table lists the event types that can be specified and some of the associated filter fields.
Note
Filter fields are not specified in this command, as all fields for the event type are dropped.
Event Type | Description | Filter Field Examples |
|---|---|---|
| HTTP events |
|
| SMTP events |
|
| DNP3 events |
|
| DNS events |
|
| Distributed Computing Environment Remote Procedure Call (DCE-RPC) events |
|
| File information events |
|
| Flow events |
|
| Internet Message Access Protocol (IMAP) events |
|
| POP3 (Post Office Protocol) events |
|
| Internet Relay Chat (IRC) events |
|
| Modbus events |
|
| Remote Desktop Protocol (RDP) events |
|
| Real Time Streaming Protocol (RTSP) events |
|
| Server Message Block (SMB) events |
|
| SMB2 events |
|
| Secure Shell (SSH) events |
|
| File Transfer Protocol (FTP) events |
|
| TLS events |
|
| MySQL events |
|
| Kerberos (KRB5) events |
|
| SOCKS events |
|
| All event types | None |
Note
Helix integration is not supported on the NX x3xx appliances and the NX 10000 appliance.
Important
Make sure the Evidence Collector module is enabled before you add or delete event filter rules. Use the
show tapsender statuscommand.
Important
Your event filter configuration changes will not take effect until you apply the changes. The status
pendingormark_deletedappears in theshow event-filter tapsender configuration <eventType>command output if you did not apply the changes.
Syntax
[no] event-filter tapsender filter-name <eventType> drop
Parameters
no
Deletes the filter rule.
<eventType>
The event type.
drop
Filters out events that match the specified event type.
Examples
The following example sets a rule to filter out all DNS events:
hostname (config) # event-filter tapsender filter-name dns drop hostname (config) # event-filter tapsender config apply
The following example sets a rule to filter out all events for all event types:
hostname (config) # event-filter tapsender filter-name all drop
This form of the command is automatically applied and does not require the event-filter tapsender config apply command.
The following example removes the rule for filtering out all DNS events:
hostname (config) # no event-filter tapsender filter-name dns drop hostname (config) # event-filter tapsender config apply
The following example removes the rule for filtering out all event types:
hostname (config) # no event-filter tapsender filter-name all drop
This form of the command is automatically applied and does not require the event-filter tapsender config apply command.
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.1.2