Filters

Filter resources are used to select events based on user-defined conditions.

This is not true only when filters are used in the collector service, in which the filters select all events that DO NOT satisfy filter conditions.

Filters can be used in collector services, enrichment rule resources, aggregation rule resources, response rule resources, correlation rule resources, and destination resources either as separate filter resources or as built-in filters stored in the service or resource where they were created.

Available settings for filter resources:

Settings of conditions:

The available operand kinds depends on whether the operand is left (L) or right (R).

Available operand kinds for left (L) and right (R) operands

Operator

Event field type

Active list type

Dictionary type

Constant type

List type

TI type

=

L,R

L,R

L,R

R

R

L,R

>

L,R

L,R

L,R

R

 

L,R

>=

L,R

L,R

L,R

R

 

L,R

<

L,R

L,R

L,R

R

 

L,R

<=

L,R

L,R

L,R

R

 

L,R

contains

L,R

L,R

L,R

R

R

L,R

startsWith

L,R

L,R

L,R

R

R

L,R

endsWith

L,R

L,R

L,R

R

R

L,R

match

L

L

L

R

R

L

inSubnet

L,R

L,R

L,R

R

R

L,R

inCategory

L

L

L

R

R

 

inActiveDirectoryGroup

L

L

L

R

R

 

inActiveList

 

L

 

 

 

 

TIDetect

 

 

 

 

 

 

Page top