This section covers the following information:
About event filter rules
When you enable integration between Helix and the Network Security appliance, the appliance passes events to Helix for further analysis. If you have events that you do not want to analyze further, you can set event filter rules so that events that match the filter criteria are not sent to Helix.
Several event filter rules are set by default and you can add custom event filter rules. You can delete default and custom rules if you want to stop filtering out the events affected by those rules.
You can configure event filter rules using the CLI or API. For information on using the API, see the Trellix API Reference Guide.
Usage guidelines
Follow these usage guidelines when you configure the event filter rules:
A maximum of 64 custom filter rules can be configured for each event type.
A back slash (\) in a regular expression is always the escape character.
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Dynamic Threat Intelligence (DTI) Cloud
An active subscription to Helix
Verify that you have specified a valid hostname for the VPC within an AWS endpoint. For details about how to configure the VPC within an AWS endpoint, see Configuring the VPC within an AWS endpoint using the Web UI or Configuring the VPC within an AWS endpoint Using the CLI .
The following table lists the event types and some of the associated filter fields.
Event Type | Description | Filter Field Examples |
|---|---|---|
| HTTP events |
|
| SMTP events |
|
| DNP3 events |
|
| DNS events |
|
| Distributed Computing Environment Remote Procedure Call (DCE-RPC) events |
|
| File information events |
|
| Flow events |
|
| Internet Message Access Protocol (IMAP) events |
|
| POP3 (Post Office Protocol) events |
|
| Internet Relay Chat (IRC) events |
|
| Modbus events |
|
| Remote Desktop Protocol (RDP) events |
|
| Real Time Streaming Protocol (RTSP) events |
|
| Server Message Block (SMB) events |
|
| SMB2 events |
|
| Secure Shell (SSH) events |
|
| File Transfer Protocol (FTP) events |
|
| TLS events |
|
| MySQL events |
|
| Kerberos (KRB5) events |
|
| SOCKS events |
|
| All event types | None |
| RADIUS (Remote Authentication Dial-In User Service) events |
|
| DHCP events |
|
| SIP Protocols |
|