Displays the default event filter rule configuration. Event rules filter out all events that are sent from an Network Security appliance to Helix Enterprise for a specified event type or for all event types.
Note
Helix Enterprise integration is not supported on the NX x3xx appliances and the NX 10000 appliance.
Syntax
show event-filter tapsender configuration default
Parameters
None
Output fields
The following table describes the output fields for this command.
Field | Description |
|---|---|
status | Whether the custom filter rule or default rule is "active", "pending", or "mark_deleted". |
type | The filter type, "default" or "custom" |
pending_op | Shows the pending operation if the filter has not yet been applied. |
filter name | The event type to filter out. |
field | The event field to filter out. |
op_type | Type of operation to use to filter the event field value, such as "equals" or "contains". |
index | Index value of the filter rule. |
value | The event field value to filter out. |
Example
The following example shows the default event filter rules.
hostname # show event-filter tapsender configuration default Event Filter Configuration Default filter version : 1 status type pending_op filter name field op_type index value active default flow app_proto equals 0 dns active default dns dns.rrtype equals 0 SRV active default dns dns.rrname contains 1 .in-addr.arpa active default dns dns.rrname contains 2 outlook.office365.com active default dns dns.rrname contains 3 .live.com active default dns dns.rrname contains 4 ctldl.windowsupdate.com active default dns dns.rrname contains 5 crl.microsoft.com active default dns dns.rrname contains 6 wpad active default fileinfo fileinfo.filename regex 0 ^(?i).*\Q\policies\\E.*$ active default fileinfo fileinfo.filename regex 1 ^(?i).*\Q\sites.xml\E.*$ active default fileinfo fileinfo.md5 equals 2 2e7db2a31d0e3da4b25f49b9542a2e1a Summary: Total: 11
User role
Admin, Operator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.1