The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing the statistics for event filters using the CLI

Prev Next

Use the commands in this topic to view the statistics for events filtered out by the event filter based on event filter rules. The statistics include the following:

  • Total number of incoming events generated on the Network Security appliance and passed to the event filter.

  • Total number of outgoing events sent to Helix after events were filtered out by the event filter rules.

  • Total number of incoming events for each event type.

  • Total number of outgoing events for each event type.

Prerequisites
  • Administrator, Operator, Monitor, or Analyst access to the Network Security appliance

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud

  • An active subscription to Helix

  • Verify that you have specified a valid hostname for the VPC within an AWS endpoint. See Configuring the VPC within an AWS endpoint using the CLI .

To view the statistics for the event filters:
  1. Go to CLI enable mode:

    hostname > enable

  2. View the statistics for the incoming and outgoing events.

    hostname # show event-filter tapsender stats
    Event Filter Statistics:
    Total Event In:   1048
    Total Event out:  1041
    
    EVENT-TYPE      EVENT-IN          EVENT-OUT
    rtsp                   8                  8
    http                  10                 10
    fileinfo              11                 11
    flow                 927                922
    dns                   20                 18
    pop3                   5                  5
    smb                   67                 67