The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing the event filter configuration using the CLI

Prev Next

Use the commands in this topic to view the event filter configuration.

Prerequisites
  • Administrator or Operator access to the Network Security appliance

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud

  • An active subscription to Helix

  • Verify that you have specified a valid hostname for the VPC within an AWS endpoint. See Configuring the VPC within an AWS endpoint using the CLI .

To view the configured event filters:
  1. Go to CLI configuration mode.

    hostname > enable 
    hostname # configure terminal
  2. View the event filter configuration.

    • To view the default event filters configured:

      hostname (config) # show event-filter tapsender configuration default

    • To view default and custom event filters configured for an event type:

      hostname (config) # show event-filter tapsender configuration <eventType>

    • To view the current configuration for the show event-filter tapsender configuration all drop command, which sets a rule to filter out all events for all event types:

      hostname (config) # show event-filter tapsender configuration all

      If the rule is set, the following output is displayed:

      Filtering all events: Yes

      If the rule is not set, the following output is displayed:

      Filtering all events: No

Examples

This example shows the default event filters configured:

hostname (config) # show event-filter tapsender configuration default

Event Filter Configuration
Default filter version : 1
status  type   pending_op filter name field             op_type  index  value                         
-------------------------------------------------------------------------------------------------------------
active  default           flow        app_proto          equals    0     dns                        
active  default           dns         dns.rrtype         equals    0     SRV                      
active  default           dns         dns.rrname         contains  1     .in-addr.arpa               
active  default           dns         dns.rrname         contains  2     outlook.office365.com    
active  default           dns         dns.rrname         contains  3     .live.com                   
active  default           dns         dns.rrname         contains  4     ctldl.windowsupdate.com    
active  default           dns         dns.rrname         contains  5     crl.microsoft.com            
active  default           dns         dns.rrname         contains  6     wpad                         
active  default           fileinfo    fileinfo.filename  regex     0     ^(?i).*\Q\policies\\E.*$     
active  default           fileinfo    fileinfo.filename  regex     1     ^(?i).*\Q\sites.xml\E.*$     
active  default           fileinfo    fileinfo.md5       equals    2 	 2e7db2a31d0e3da4b25f49b9542a2e1a
Summary:
	Total: 11

This example shows the event filter rules configured for http.

hostname (config) # show event-filter tapsender configuration http
Event Filter Configuration
Default filter version : 1
status    type      pending_op    filter name    field               op_type       index   value                         
----------------------------------------------------------------------------------------------------------------
active    custom                  http           http.http_method    contains      0       GET
active    custom                  http           http.http_method    contains      1       POST                          
Summary:
	Total active:                   2
	Total pending:                  0
	Total marked for deletion:      0
	Total:                          2