Filtering events

The toolbar above each events list narrows what you see: by time, machine, severity, source, label, tag and more. This page describes every toolbar control and how filters are kept in the page address.

How filters work

Filters only change what the list shows; nothing stored is changed or deleted. Every filter you set applies together with the others, and the list reloads as soon as you change one.

The toolbar has two parts. The first belongs to the list you are on and differs a little per product. The second (Show, Label, Tag, Live and Reset) is shared by every list. Less frequent filters, such as an exact time range, live in Advanced search below the toolbar.

Layout

On es-python, Layout switches between List (the table) and Map (the same events drawn as a graph of sources, files and sinks). Every filter applies to both. See Events map.

Quick ranges

The Quick buttons (1m, 10m, 1h, 24h, 7d) show only events from the last minute, ten minutes, hour, day or week. Click the lit button again to turn the range off.

A quick range replaces any From / To you typed in Advanced search, and typing a time there turns the quick range off, so only one time filter is ever active. A quick range keeps moving with the clock: "last hour" always means the hour before the latest reload.

Whitelist Repr

Whitelist Repr (es-python) shows only events whose sink label matches the regular expression you type, ignoring case. Despite its name it matches the label shown in the Event column (such as os system), not the value.

For example exec|eval|system keeps code and command execution events. The box gets a red border while the pattern is not a valid regular expression.

Blacklist Repr

Blacklist Repr (es-python) is the opposite of Whitelist Repr: it hides events whose sink label matches your regular expression, ignoring case. For example ^io hides file-operation events. Use both boxes together to keep a family of events and drop part of it.

To hide something permanently rather than for this visit, block it from the row menu or add a filter on the Filters page.

Machine

Machine narrows the list to one of your machines. Click it and type to search when you have many; the newest machines are listed first. On some products the same control is called Browser, Service or Project, and it lists only machines of that product.

On es-python, the machine you pick here also scopes the run picker.

Runs

Runs (es-python) opens the run picker, where you choose one program invocation and see only the events it produced. See Runs.

Severity

Severity keeps only the severities you tick: Critical, High, Medium, Low, Info. Tick one or more; with none ticked, every severity is shown. The button shows what you picked, or "N selected" past two.

Source

Source (es-python) keeps only events whose untrusted data came from the sources you tick. Ticking none shows every source.

Option Data that came from
Socket / Network a network connection
File reading a file
Stdin standard input (keyboard or pipe)
Environment an environment variable
Command-line args the program's arguments
Manual (make_vuln) a value you marked untrusted in code
Fuzzer input generated by the fuzzer
Foreign code code loaded from files other users can write

Each source is explained on Taint sources.

Can cause XSS

Can cause XSS (es-chromium) shows only events whose sink can end in running script in the page: markup writes, code sinks, script URLs, attribute writes and navigations. Storage and cookie writes are hidden because the write itself runs nothing; if the value is read back into a dangerous place later, that is reported as its own event.

Show

Show chooses between the events EyalSec could not prove safe (Live only, the default), the ones it could (Suppressed only), or both (All events). The badge beside it counts the suppressed events. See Suppressed events.

Label

Label narrows every list to events carrying one of your own labels. All labels turns it off.

Tag

Tag narrows every list to one impact tag, the vulnerability class of the flow, such as sqli, xss or command injection. All tags turns it off.

Tags are worked out when the list is built rather than stored, so on a rare class the list searches backwards through your history and can show Searching. Reached date for a moment before the first row appears.

The list offers every class, including ones you have blocked. Picking a class you blocked gives an empty list, because the block still hides it; unblock it on the Filters page to see those events again. You can also pick a tag from an event's row menu.

Live

The Live · 2s button reloads the list every two seconds. Click it to pause (it then reads Paused); click again to resume and reload at once. See Live updates.

Reset

Reset clears every filter on every list at once: the toolbar, the quick range, Show (back to Live only), Label, Tag, and everything in Advanced search. It does not touch your saved searches or the filters on the Filters page.

Filters active

When you have filters on the Filters page, an amber N filters active badge appears next to Reset. Those are standing rules applied to every query, not settings of this visit, so Reset does not clear them. Click the badge to open the Filters page and review them.

Filters live in the address

Every filter you set is written into the page address. You can bookmark a filtered view, send the link to a colleague who has access to the same account, or reload and land back where you were.

The address carries the list, the layout, the toolbar filters, the time range, the scope and the Advanced search conditions (as the short text form, q=). One exception: changing the Label filter updates the address only once you change another filter too, so check the label before sharing a link. A colleague only sees events that their own account can see.

When a search is slow

EyalSec examines your history in slices so no single request takes long. With a very selective filter, the first slices may hold no matches, and the last row of the list reads Searching. Reached date while it keeps looking further back. Rows appear as soon as matches are found. If the list says No events match the current filters, nothing matched at all.

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo