Use the CLI commands in this topic to delete a rule from an event filter list. You also can delete an event filter using its index value in an event filter list. For details about the event types and some of the associated filter field examples, see Adding event filter rules using the CLI .
Important
Your event filter configuration changes will not take effect until you apply the changes. Use the
event-filter tapsender config applycommand. The statusmark_deletedappears in theshow event-filter tapsender configurationcommand output if you did not apply the changes.
Go to CLI configuration mode.
hostname > enablehostname # configure terminalDelete a filter rule based on an event type from the event filter configuration.
hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName>where
<eventType>is the event type you want to filter and<event_fieldName>is the supported JSON event field that is associated with the event type.For details about the valid event types, see Adding event filter rules using the CLI .
Delete a rule that filters on JSON values using operations.
To delete the corresponding field that begins with the JSON value and event type:
hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> begins_with <operationValue>To delete the corresponding field that ends with the JSON value and event type:
hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> ends_with <operationValue>To delete the corresponding field that contains the JSON value and event type:
hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> contains <operationValue>To delete the corresponding field that equals the JSON value and event type:
hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> equals <operationValue>To delete the corresponding field using a regular expression to match the JSON value and event type:
hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> regex <regular_expression>
Apply your changes to the event filter configuration.
hostname (config) # event-filter tapsender config applyVerify the status of the event filter configuration.
hostname (config) # show event-filter tapsender configuration
Examples
This example shows how to delete the filter rule based on the match criteria for the DNS event from the event filter configuration:
hostname (config) # no event-filter tapsender filter-name dns match dns.rrname contains .in-addr.arpa
This example shows how to delete the filter rule based on the match criteria for the flow event from the event filter configuration:
hostname (config) # no event-filter tapsender filter-name flow match app_proto equals dns
This example shows how to delete the filter rule based on the match criteria for the file information event from the event filter configuration:
hostname (config) # no event-filter tapsender filter-name fileinfo match fileinfo.filename contains \sites.xml
This example verifies that the filter rule on match criteria for \sites.xml was deleted.
hostname (config) # show event-filter tapsender configuration
Event Filter Configuration
status filter name field op_type index value active default dns dns.rrname contains 2 .in-addr.arpaactive default dns dns.rrname contains 3 outlook.office365.comactive default dns dns.rrname contains 4 .live.comactive default fileinfo fileinfo.filename contains 1 \policies\active default fileinfo fileinfo.md5 equals 3 2e7db2a31d0e3da4b25f49b9542a2e1aactive default flow app_proto equals 1 dns
To delete an event filter using its index value in an event filter list:
Go to CLI configuration mode.
hostname > enablehostname # configure terminalVerify the configuration for the event filter.
hostname (config) # show even-filter tapsender configurationEvent Filter Configuration status filter name field op_type index value ---------------------------------------------------------------------------------- active default dns dns.rrname contains 2 .in-addr.arpa active default dns dns.rrname contains 3 outlook.office365.com active default dns dns.rrname contains 4 .live.com active default fileinfo fileinfo.filename contains 1 \policies\ active default fileinfo fileinfo.md5 equals 3 2e7db2a31d0e3da4b25f49b9542a2e1a active default flow app_proto equals 1 dns
Delete an event filter using its index value.
hostname (config) # no event-filter tapsender filter name <eventType> index <indexNumber>Apply your changes for the event filter configuration.
hostname (config) # event-filter tapsender config applyVerify the status of the event filter configuration.
hostname (config) # show event-filter tapsender configuration
Examples
This example shows how to delete a custom filter rule for the HTTP event using the index value of 0 from the event filter configuration:
hostname (config) # no event-filter tapsender filter-name http index 0
This example shows that the custom filter fule for the HTTP event was deleted.
hostname (config) # show event-filter tapsender configuration
Event Filter Configuration status filter name field op_type index value --------------------------------------------------------------------------------- active default dns dns.rrname contains 2 .in-addr.arpa active default dns dns.rrname contains 3 outlook.office365.com active default dns dns.rrname contains 4 .live.com active default fileinfo fileinfo.filename contains 1 \policies\ active default fileinfo fileinfo.filename contains 1 \sites.xml> active default fileinfo fileinfo.md5 equals 3 2e7db2a31d0e3da4b25f49b9542a2e1a active default flow app_proto equals 1 dns