Event filters

edit

Event filters allow admins to filter endpoint events that you do not need or want stored in Elasticsearch — for example, those with high volumes. By creating event filters, you can optimize your storage in Elasticsearch. All endpoint events have the endpoint.events.network field.

Since an event filter blocks an event from streaming to Elasticsearch, be conscious of event filter conditions you set and any existing rule conditions. If there is too much overlap, the rule may run less frequently than specified and, therefore, will not trigger the corresponding alert for that rule. This is the expected behavior of event filters.

Create event filters from the Hosts page or the Event filters page.

  1. To create an event filter from the Hosts page:

    1. Go to ExploreHosts.
    2. Select the Events tab to view the Events table.
    3. Find the event to create a filter, click the More actions button (…​), then click Add Endpoint event filter.

      Since you can only create filters for endpoint events, be sure to filter the Events table to display events generated by the Elastic Endpoint.
      In the KQL search bar, enter the following query: event.dataset : endpoint.events.network.

    4. Proceed to step 3.
  2. To create an event filter via the Event filters page:

    1. Go to ManageEvent filters.
    2. Click Add Event Filter. The Add event filter flyout opens.

      event filter
  3. Enter a name for the event filter.
  4. Depending on which page you add the filter, either modify the pre-populated conditions or add new conditions that define when Elastic Security filters events. You can define multiple conditions with AND relationships. You can also add nested conditions. In the image above, the event filter excludes events whose event.category field is network, and whose process.executable field is the same as the specified path.
  5. Add a new comment that describes or identifies the filter (optional).
  6. Click Add event filter. The new filter is added to the Event filters list.

View and manage event filters

edit

The Event filters list allows you to view and manage all endpoint event filters that have been added. To view the Event filters list, go to ManageEvent filters. Event filters appear in reverse chronological order, with the most recently created filter at the top. Each filter has its own entry, which displays details such as the filter name, operating system, date created, and the filter conditions.

To refine the Event filters list, enter a query in the search bar. You can search the by name, comments, or the value of a field.

event filters list

Edit an event filter

edit

To edit an event filter:

  1. Click the actions button (…​) for the event filter you want to edit, then select Edit event filter.
  2. Modify details or conditions as needed.
  3. Click Update event filter.

Delete an event filter

edit

To delete an event filter:

  1. Click the actions button (…​) for the event filter you want to delete, then select Delete event filter.
  2. On the dialog that opens, verify that you are removing the correct event filter, then click Remove event filter. A confirmation message is displayed.