Use the CLI commands in this topic to add your own custom filter rules or reset the rules to the default rules that Trellix provides to an event filter list.
The following table lists the event types and some of the associated filter field examples:
Event Type | Description | Filter Field Examples |
|---|---|---|
| HTTP events |
|
| SMTP events |
|
| DNP3 events |
|
| DNS events |
|
| Distributed Computing Environment Remote Procedure Call (DCE-RPC) events |
|
| File information events |
|
| Flow events |
|
| Internet Message Access Protocol (IMAP) events |
|
| POP3 (Post Office Protocol) events |
|
| Internet Relay Chat (IRC) events |
|
| Modbus events |
|
| Remote Desktop Protocol (RDP) events |
|
| Real Time Streaming Protocol (RTSP) events |
|
| Server Message Block (SMB) events |
|
| SMB2 events |
|
| Secure Shell (SSH) events |
|
| File Transfer Protocol (FTP) events |
|
| TLS events |
|
| MySQL events |
|
| Kerberos (KRB5) events |
|
| SOCKS events |
|
| All event types | None |
| RADIUS (Remote Authentication Dial-In User Service) events |
|
| DHCP events |
|
| SIP Protocols |
|
Important
Your event filter configuration changes will not take effect until you apply the pending changes. Use the
event-filter tapsender config applycommand. The statuspendingappears in theshow event-filter tapsender configurationcommand output if you did not apply the changes.
Go to CLI configuration mode.
hostname > enable hostname # configure terminalSpecify a filter rule based on the event type you want to filter.
hostname (config) # event-filter tapsender filter-name <eventTyoe> match <event_fieldName>where
<eventType>is the event type you want to filter and<event_fieldName>is the supported JSON event field that is associated with the event type.Specify the type of operation to filter out the JSON value for the corresponding field.
To filter out the corresponding field that begins with the JSON value and event type:
hostname (config) # event-filter tapsender filter-name <eventType> match <event_fieldName> begins_with <operationValue>To filter out the corresponding field that ends with the JSON value and event type:
hostname (config) # event-filter tapsender filter-name <event_Type> match <event_fieldName> ends_with <operationValue>To filter out the corresponding field that contains the JSON value and event type:
hostname (config) # event-filter tapsender filter-name <eventType> match <event_fieldName contains <operationValue>To filter out the corresponding field that equals the JSON value and event type:
hostname (config) # event-filter tapsender filter-name <eventType> match <event_fieldName equals <operationValue>To filter out the corresponding field using a regular expression to match the JSON value event type:
hostname (config) # event-filter tapsender filter-name <eventType> match <event_fieldName> regex <regular_expression>
Apply your changes to the event filter configuration.
hostname (config) # event-filter tapsender config applyVerify the status of the event filter configuration.
hostname (config) # show event-filter tapsender configuration
Examples
This example shows how to add multiple filter rules to filter out DNS event matches for the dns.rrname field:
hostname (config) # event-filter tapsender filter-name dns match dns.rrname contains .in-addr.arpa
hostname (config) # event-filter tapsender filter-name dns match dns.rrname contains outlook.office365.com
hostname (config) # event-filter tapsender filter-name dns match dns.rrname contains .live.com
This example shows how to add multiple filter rules to filter out file information event matches for the fileinfo.filename and fileinfo.md5 fields.
hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.filename contains \policies\
hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.md5 equals 2e7db2a31d0e3da4b25f49b9542a2e1a
hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.filename contains \sites.xml
This example shows how to add the filter rule to filter out file information event matches for the fileinfo.filename and fileinfo.md5 fields.
hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.filename contains \policies\
hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.md5 equals 2e7db2a31d0e3da4b25f49b9542a2e1a
hostname (config) # event-filter tapsender filter-name fileinfo match fileinfo.filename contains \sites.xml
This example shows how to add the filter rule to filter out the flow event matches for the app_proto field.
hostname (config) # event-filter tapsender flow match app_proto equals dns
This example shows an event filter tapsender configuration for all events.
hostname (config) # show event-filter tapsender configuration all
Event Filter Configuration status filter name field op_type index value ---------------------------------------------------------------------------- active default dns dns.rrname contains 2 .in-addr.arpa active default dns dns.rrname contains 3 outlook.office365.com active default dns dns.rrname contains 4 .live.com active default fileinfo fileinfo.filename contains 1 \policies\ active default fileinfo fileinfo.filename contains 1 \sites.xml> active default fileinfo fileinfo.md5 equals 3 2e7db2a31d0e3da4b25f49b9542a2e1a active default flow app_proto equals 1 dns