The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deleting event filter rules using the CLI

Prev Next

Use the CLI commands in this topic to delete a rule from an event filter list. You also can delete an event filter using its index value in an event filter list. For details about the event types and some of the associated filter field examples, see Adding event filter rules using the CLI .

Important

Your event filter configuration changes will not take effect until you apply the changes. Use the event-filter tapsender config apply command. The status mark_deleted appears in the show event-filter tapsender configuration command output if you did not apply the changes.

To delete an event from an event filter list:
  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Delete a filter rule based on an event type from the event filter configuration.

    hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName>

    where <eventType> is the event type you want to filter and <event_fieldName> is the supported JSON event field that is associated with the event type.

    For details about the valid event types, see Adding event filter rules using the CLI .

  3. Delete a rule that filters on JSON values using operations.

    • To delete the corresponding field that begins with the JSON value and event type:

      hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> begins_with <operationValue>

    • To delete the corresponding field that ends with the JSON value and event type:

      hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> ends_with <operationValue>

    • To delete the corresponding field that contains the JSON value and event type:

      hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> contains <operationValue>

    • To delete the corresponding field that equals the JSON value and event type:

      hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> equals <operationValue>

    • To delete the corresponding field using a regular expression to match the JSON value and event type:

      hostname (config) # no event-filter tapsender filter-name <eventType> match <event_fieldName> regex <regular_expression>

  4. Apply your changes to the event filter configuration.

    hostname (config) # event-filter tapsender config apply

  5. Verify the status of the event filter configuration.

    hostname (config) # show event-filter tapsender configuration

Examples

This example shows how to delete the filter rule based on the match criteria for the DNS event from the event filter configuration:

hostname (config) # no event-filter tapsender filter-name dns match dns.rrname contains .in-addr.arpa

This example shows how to delete the filter rule based on the match criteria for the flow event from the event filter configuration:

hostname (config) # no event-filter tapsender filter-name flow match app_proto equals dns

This example shows how to delete the filter rule based on the match criteria for the file information event from the event filter configuration:

hostname (config) # no event-filter tapsender filter-name fileinfo match fileinfo.filename contains \sites.xml

This example verifies that the filter rule on match criteria for \sites.xml was deleted.

hostname (config) # show event-filter tapsender configuration

Event Filter  Configuration
status   filter    name     field             op_type   index  value

active  default   dns      dns.rrname         contains  2     .in-addr.arpaactive  default   dns      dns.rrname         contains  3      outlook.office365.comactive  default   dns      dns.rrname         contains  4     .live.comactive  default   fileinfo fileinfo.filename  contains  1     \policies\active  default   fileinfo fileinfo.md5       equals    3     2e7db2a31d0e3da4b25f49b9542a2e1aactive  default   flow     app_proto          equals    1     dns

To delete an event filter using its index value in an event filter list:

  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Verify the configuration for the event filter.

    hostname (config) # show even-filter tapsender configuration

    Event Filter  Configuration
    
    status     filter     name     field             op_type     index     value
    ----------------------------------------------------------------------------------
    active     default    dns      dns.rrname        contains    2         .in-addr.arpa
    active     default    dns      dns.rrname        contains    3         outlook.office365.com
    active     default    dns      dns.rrname        contains    4         .live.com
    active     default    fileinfo fileinfo.filename contains    1         \policies\
    active     default    fileinfo fileinfo.md5      equals      3         2e7db2a31d0e3da4b25f49b9542a2e1a
    active     default    flow     app_proto         equals      1         dns
    
    
  3. Delete an event filter using its index value.

    hostname (config) # no event-filter tapsender filter name <eventType> index <indexNumber>

  4. Apply your changes for the event filter configuration.

    hostname (config) # event-filter tapsender config apply

  5. Verify the status of the event filter configuration.

    hostname (config) # show event-filter tapsender configuration

Examples

This example shows how to delete a custom filter rule for the HTTP event using the index value of 0 from the event filter configuration:

hostname (config) # no event-filter tapsender filter-name http index 0

This example shows that the custom filter fule for the HTTP event was deleted.

hostname (config) # show event-filter tapsender configuration

Event Filter  Configuration

status     filter     name         field             op_type     index     value
---------------------------------------------------------------------------------
active     default    dns          dns.rrname        contains    2         .in-addr.arpa
active     default    dns          dns.rrname        contains    3         outlook.office365.com
active     default    dns          dns.rrname        contains    4         .live.com
active     default    fileinfo     fileinfo.filename contains    1         \policies\
active     default    fileinfo     fileinfo.filename contains    1         \sites.xml>
active     default    fileinfo     fileinfo.md5      equals      3         2e7db2a31d0e3da4b25f49b9542a2e1a
active     default    flow         app_proto         equals      1         dns