The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Adding event filter rules using the CLI

Prev Next

Use the CLI commands in this topic to add your own custom filter rules or reset the rules to the default rules that Trellix provides to an event filter list.

The following table lists the event types and some of the associated filter field examples:

Event Type

Description

Filter Field Examples

http

HTTP events

http.hostname

http.url

http.http_user_agent

smtp

SMTP events

smtp.mail_from

email.status

dnp3

DNP3 events

dnp3.type

dnp3.control.dir

dnp3.control.pri

dnp3.control.fcb

dnp3.control.fcv

dnp3.control.function_code

dnp3.src

dnp3.dst

dnp3.application.control.fir

dnp3.application.control.fin

dnp3.application.control.con

dnp3.application.control.uns

dnp3.application.control.sequence

dnp3.application.function_code

dnp3.application.complete

dns

DNS events

src_ip dns.rrname

src_port

dest_ip

dest_portdns.rdata

proto

dns.version

dns.type

dns.id

dns.flags

dns.qr

dns.rd

dns.ra

dns.rrname

dns.rrtype

dns.tx_id

dns.tx_id

dns.rcode

dns.ttl

dns.rdata

answers.rrname

answers.rrtype

answers.ttl

answers.rdata

dcerpc

Distributed Computing Environment Remote Procedure Call (DCE-RPC) events

dcerpc.interface.uuid

dcerpc.interface.version

dcerpc.interface.minor-version

fileinfo

File information events

fileinfo.filename

fileinfo.md5

fileinfo.stored

flow

Flow events

app_proto

flow.pkts_toserver

flow.pkts_toclient

imap

Internet Message Access Protocol (IMAP) events

email.status

email.from

pop3

POP3 (Post Office Protocol) events

email.status

email.from

irc

Internet Relay Chat (IRC) events

irc.user

irc.prefix

irc.cmd

modbus

Modbus events

modbus.transaction_id

modbus.protocol_id

modbus.unit_id

modbus.function_code

modbus.function_category

modbus.exception_code

modbus.diag_subfunction

modbus.mei

modbus.response

modbus.read.address

modbus.read.quantity

modbus.write.address

modbus.write.quantity

modbus.write.count

rdp

Remote Desktop Protocol (RDP) events

src_ip

src_port

dest_ip

dest_port

proto

rdp.event_type

rdp.client.version

rdp.client.desktop_width

rdp.client.desktop_height

rdp.client.color_depth

rdp.client.keyboard_layout

rdp.client.build

rdp.client.client_name

rdp.client.keyboard_type

rdp.client.function_keys

rdp.client.product_id

rdp.client.capabilities

rdp.client.id

rdp.channels

rtsp

Real Time Streaming Protocol (RTSP) events

rtsp.request.type

rtsp.request.accept

rtsp.response.content_type

smb

Server Message Block (SMB) events

smb.command

smb.command_str

smb.status

smb2

SMB2 events

smb2.status

smb2.session_setup.type

smb2.session_setup.authenticate.domain

ssh

Secure Shell (SSH) events

ssh.client.proto_version

ssh.client.software_version

ssh.server.proto_version

ftp

File Transfer Protocol (FTP) events

ftp.user

ftp.pass

ftp.port

tls

TLS events

tls.subject

tls.version

tls.notbefore

mysql

MySQL events

mysql.command

mysql.arguments

mysql.success

mysql.rows_affected

mysql.response_error

krb5

Kerberos (KRB5) events

krb5.request_type

krb5.client

krb5.client_realm

krb5.server

krb5.server_realm

krb5.from

krb5.till

krb5.cipher

krb5.forwardable

krb5.renewable

krb5.success

krb5.error_code

socks

SOCKS events

socks.ver4.request.command

socks.ver4.request.remote_port

socks.ver4.request.remote_address

socks.ver4.request.username

socks.ver4.request.remote_V4A_domain_name

socks.ver4.response.result

socks.ver4.response.port

socks.ver4.response.address

socks.ver5.request.method_count

socks.ver5.request.method_0

socks.ver5.request.method_1

socks.ver5.request.method_2

socks.ver5.request.method_3

socks.ver5.request.method_4

socks.ver5.request.method_5

socks.ver5.request.method_mismatch

socks.ver5.request.username_length

socks.ver5.request.username

socks.ver5.request.password_length

socks.ver5.request.password

socks.ver5.request.command

socks.ver5.request.address_type

socks.ver5.request.remote_address

socks.ver5.request.remote_port

socks.ver5.request.remote_name

socks.ver5.request.remote_name_length_field

socks.ver5.request.remote_name_length

socks.ver5.response.accepted_method

socks.ver5.response.unexpected_method

socks.ver5.response.status

socks.ver5.response.result

socks.ver5.response.address_type

socks.ver5.response.remote_name_length

socks.ver5.response.remote_address

socks.ver5.response.remote_port

all

All event types

None

radius

RADIUS (Remote Authentication Dial-In User Service) events

radius.request.code

radius.request.username

radius.request.remote.ip

radius.request.remote.port

radius.request.remote.port.type

radius.request.remote.port_id

radius.request.service_type

radius.request.Called_MAC

radius.reply.code

radius.success

dhcp

DHCP events

src_ip

src_port

dest_ip

dest_port

proto

dhcp.type

dhcp.id

dhcp.client_mac

dhcp.assigned_ip

dhcp.client_ip

dhcp.relay_ip

dhcp.next_server_ip

dhcp.dhcp_type

dhcp.subnet_mask

dhcp.routers

dhcp.hostname

dhcp.lease_time

dhcp.renewal_time

dhcp.rebinding_time

dhcp.client_id

dhcp.dns_servers

sip

SIP Protocols

src_ip

src_port

dest_ip

dest_port

proto

sip.method

sip.uri

sip.version

sip.request_line

sip.code

sip.reason

sip.response_line

Important

Your event filter configuration changes will not take effect until you apply the pending changes. Use the event-filter tapsender config apply command. The status pending appears in the show event-filter tapsender configuration command output if you did not apply the changes.

To add rules to an event filter list:
  1. Go to CLI configuration mode.

    hostname > enable hostname # configure terminal

  2. Specify a filter rule based on the event type you want to filter.

    hostname (config) # event-filter tapsender filter-name <eventTyoe> match <event_fieldName>

    where <eventType> is the event type you want to filter and <event_fieldName> is the supported JSON event field that is associated with the event type.

  3. Specify the type of operation to filter out the JSON value for the corresponding field.

    • To filter out the corresponding field that begins with the JSON value and event type:

      hostname (config) # event-filter tapsender filter-name <eventType> match <event_fieldName> begins_with <operationValue>

    • To filter out the corresponding field that ends with the JSON value and event type:

      hostname (config) # event-filter tapsender filter-name <event_Type> match <event_fieldName> ends_with <operationValue>

    • To filter out the corresponding field that contains the JSON value and event type:

      hostname (config) # event-filter tapsender filter-name <eventType> match <event_fieldName contains <operationValue>

    • To filter out the corresponding field that equals the JSON value and event type:

      hostname (config) # event-filter tapsender filter-name <eventType> match <event_fieldName equals <operationValue>

    • To filter out the corresponding field using a regular expression to match the JSON value event type:

      hostname (config) # event-filter tapsender filter-name <eventType> match <event_fieldName> regex <regular_expression>

  4. Apply your changes to the event filter configuration.

    hostname (config) # event-filter tapsender config apply

  5. Verify the status of the event filter configuration.

    hostname (config) # show event-filter tapsender configuration

Examples

This example shows how to add multiple filter rules to filter out DNS event matches for the dns.rrname field:

hostname (config) # event-filter tapsender filter-name dns match dns.rrname contains .in-addr.arpa

hostname (config) # event-filter tapsender filter-name dns match dns.rrname contains outlook.office365.com

hostname (config) # event-filter tapsender filter-name dns match dns.rrname contains .live.com

This example shows how to add multiple filter rules to filter out file information event matches for the fileinfo.filename and fileinfo.md5 fields.

hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.filename contains \policies\

hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.md5 equals 2e7db2a31d0e3da4b25f49b9542a2e1a

hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.filename contains \sites.xml

This example shows how to add the filter rule to filter out file information event matches for the fileinfo.filename and fileinfo.md5 fields.

hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.filename contains \policies\

hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.md5 equals 2e7db2a31d0e3da4b25f49b9542a2e1a

hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.filename contains \sites.xml

This example shows how to add the filter rule to filter out the flow event matches for the app_proto field.

hostname (config) # event-filter tapsender flow match app_proto equals dns

This example shows an event filter tapsender configuration for all events.

hostname (config) # show event-filter tapsender configuration all
Event Filter  Configuration

status     filter     name     field             op_type     index     value
----------------------------------------------------------------------------
active     default    dns      dns.rrname        contains    2         .in-addr.arpa
active     default    dns      dns.rrname        contains    3         outlook.office365.com
active     default    dns      dns.rrname        contains    4         .live.com
active     default    fileinfo fileinfo.filename contains    1         \policies\
active     default    fileinfo fileinfo.filename contains    1         \sites.xml>
active     default    fileinfo fileinfo.md5      equals      3         2e7db2a31d0e3da4b25f49b9542a2e1a
active     default    flow     app_proto         equals      1         dns