show event-filter tapsender configuration <event-type>

Prev Next

Displays the event filter rule configuration for an event type. Event rules filter out all events that are sent from a Network Security appliance to Helix Enterprise for a specified event type or for all event types.

Note

Helix Enterprise integration is not supported on the NX x3xx appliances and the NX 10000 appliance.

Syntax

show event-filter tapsender configuration <event-type>

Parameters

<event-type>

The event type

Output fields

The following table describes the output fields for this command.

Field

Description

status

Whether the custom filter rule or default rule is "active", "pending", or "mark_deleted".

type

The filter type, "default" or "custom"

pending_op

Shows the pending operation if the filter has not yet been applied.

filter name

The event type to filter out.

field

The event field to filter out.

op_type

Type of operation to use to filter the event field value, such as "equals" or "contains".

index

Index value of the filter rule.

value

The event field value to filter out.

Example

The following example shows the event filter rules configured for the DNS event type, where one rule is pending deletion.

hostname # show event-filter tapsender configuration dns
Event Filter Configuration
Default filter version : 1
status    type      pending_op    filter name    field         op_type       index   value                         

active    default                 dns            dns.rrtype    equals        0       SRV                    
active    default                 dns            dns.rrname    contains      1       .in-addr.arpa           
active    default                 dns            dns.rrname    contains      2       outlook.office365.com   
active    default                 dns            dns.rrname    contains      3       .live.com               
active    default                 dns            dns.rrname    contains      4       ctldl.windowsupdate.com 
active    default                 dns            dns.rrname    contains      5       crl.microsoft.com       
active    default                 dns            dns.rrname    contains      6       wpad                  
pending   custom    mark_deleted  dns            dns.rrname    regex         7       \.live.com                    
Summary:
	Total active:                   7
	Total pending:                  1
	Total marked for deletion:      1
	Total:                          8

User role

Admin, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.2.2