show event-filter tapsender configuration default

Prev Next

Displays the default event filter rule configuration. Event rules filter out all events that are sent from an Network Security appliance to Helix Enterprise for a specified event type or for all event types.

Note

Helix Enterprise integration is not supported on the NX x3xx appliances and the NX 10000 appliance.

Syntax

show event-filter tapsender configuration default

Parameters

None

Output fields

The following table describes the output fields for this command.

Field

Description

status

Whether the custom filter rule or default rule is "active", "pending", or "mark_deleted".

type

The filter type, "default" or "custom"

pending_op

Shows the pending operation if the filter has not yet been applied.

filter name

The event type to filter out.

field

The event field to filter out.

op_type

Type of operation to use to filter the event field value, such as "equals" or "contains".

index

Index value of the filter rule.

value

The event field value to filter out.

Example

The following example shows the default event filter rules.

hostname # show event-filter tapsender configuration default 
Event Filter Configuration
Default filter version : 1
status    type    pending_op filter name  field             op_type  index value 
                        
active    default            flow         app_proto         equals   0     dns                          
active    default            dns          dns.rrtype        equals   0     SRV                          
active    default            dns          dns.rrname        contains 1     .in-addr.arpa                
active    default            dns          dns.rrname        contains 2     outlook.office365.com     
active    default            dns          dns.rrname        contains 3     .live.com                 
active    default            dns          dns.rrname        contains 4     ctldl.windowsupdate.com   
active    default            dns          dns.rrname        contains 5     crl.microsoft.com         
active    default            dns          dns.rrname        contains 6     wpad                          
active    default            fileinfo     fileinfo.filename regex    0     ^(?i).*\Q\policies\\E.*$   
active    default            fileinfo     fileinfo.filename regex    1     ^(?i).*\Q\sites.xml\E.*$  
active    default            fileinfo     fileinfo.md5      equals   2     2e7db2a31d0e3da4b25f49b9542a2e1a
Summary:
	Total: 11

User role

Admin, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.1