Kaspersky Unified Monitoring and Analysis Platform

Filters

Filter resources are used to select events based on user-defined conditions.

This is not true only when filters are used in the collector service, in which the filters select all events that DO NOT satisfy filter conditions.

Filters can be used in collector services, enrichment rule resources, aggregation rule resources, response rule resources, correlation rule resources, and destination resources either as separate filter resources or as built-in filters stored in the service or resource where they were created.

Available settings for filter resources:

  • Name (required)—a unique name for this type of resource. Must contain from 1 to 128 Unicode characters. Inline filters are created in other resources or services and do not have names.
  • Tenant (required)—name of the tenant that owns the resource.
  • Conditions settings block—here you can formulate filtering criteria by creating filter conditions and groups of filters, and by adding existing filter resources.

    You can use the Add group button to add a group of filters. Group operators can be switched between AND, OR, and NOT. Groups, conditions, and existing filter resources can be added to groups of filters.

    You can use the Add filter button to add an existing filter resource, which should be selected in the Select filter drop-down list.

    You can use the Add condition button to add a string containing fields for identifying the condition (see below).

    Conditions, groups, and filters can be deleted by using the cross button.

Settings of conditions:

  • If (required)—in this drop-down list, you can specify whether or not to use the inverted function of the operator.
  • Left operand and Right operand (required)—used to specify the values that the operator will process. The available types depend on the selected operator.

    Operands of filters

  • Operator (required)—used to select the condition operator.

    In this drop-down list, you can select the Ignore case check box if the operator should ignore the case of values. This check box is ignored if the InSubnet, InActiveList, InCategory, and InActiveDirectoryGroup operators are selected.

    Filter operators

The available operand kinds depends on whether the operand is left (L) or right (R).

Available operand kinds for left (L) and right (R) operands

Operator

Event field type

Active list type

Dictionary type

Constant type

List type

TI type

=

L,R

L,R

L,R

R

R

L,R

>

L,R

L,R

L,R

R

 

L,R

>=

L,R

L,R

L,R

R

 

L,R

<

L,R

L,R

L,R

R

 

L,R

<=

L,R

L,R

L,R

R

 

L,R

contains

L,R

L,R

L,R

R

R

L,R

startsWith

L,R

L,R

L,R

R

R

L,R

endsWith

L,R

L,R

L,R

R

R

L,R

match

L

L

L

R

R

L

inSubnet

L,R

L,R

L,R

R

R

L,R

inCategory

L

L

L

R

R

 

inActiveDirectoryGroup

L

L

L

R

R

 

inActiveList

 

L

 

 

 

 

TIDetect