Filters

The Filters page holds the standing settings for one product: the taint sources and rules that apply to every machine, what you have blocked from view, and what counts as a new event. This page walks through each part of it.

The Filters page

Each product on your account has its own Filters page. Open it from Filters in the sidebar; if your account has both products, Filters opens into one link per product, and tabs at the top of the page switch between them.

The page opens with a one-line description of the product. When the product cannot act on part of what the page offers, a highlighted note under it says so (see Product notes). Below that are three sections:

Section What it holds Applies to
Sources & rules account-wide taint sources, event context and rules your whole account
Blocked events events you blocked from the Events page this product (or both, when marked all engines)
Unique event the fields that decide what counts as a new event this product

Blocked events

Blocked events lists everything you have blocked from view for this product. A block hides an event, and every event like it, from your events lists. You create blocks on the Events page: right-click a row, or open its row menu, and choose Block this sink, Block this source or Block this tag (see the row menu). On es-python the row menu makes a rule instead of a block: its Rule group adds the event to Sources & rules further up this page, in the mode you pick (see Rule).

Blocks change what you see, never what is recorded. A blocked event is still stored and still counts, and it reappears as soon as you pause or remove the block. When nothing is blocked, the section says so and reminds you how to block.

Each row of the list has these columns:

What

What is the block's label: the sink, source or tag you blocked, as it appeared on the event. A block marked all engines applies to both products' events lists, not only this one.

Scope

Scope says what kind of thing the block matches. Hover over it for a reminder.

Scope Hides
sink every event at this sink (from Block this sink)
source every event from this taint source (from Block this source)
tag every event carrying this impact tag (from Block this tag)

Block this source is offered only on rows that name a source. es-python rows have no Block items at all; they have the Rule group instead.

Pattern

Pattern is the regular expression the block matches against the sink, source or tag. It is filled in for you when you block from the Events page.

State

State is a switch that turns a block on (blocking) or off (paused) without deleting it. A paused block hides nothing, so its events are listed again until you switch it back on.

Unblock

Unblock removes the block for good, after you confirm. Matching events reappear on the Events page. To hide them again, block them again from the Events page.

Unique event

Unique event decides when a new detection opens a new row in this product's events list and when it only adds to an existing row's count. It has its own page: see Unique event.

Sources & rules for every machine

Sources & rules holds your global settings: the taint sources, event context and rules that apply to every machine, unless a machine has its own setting. They are the same controls as in a machine's Configure window, applied account-wide.

These settings belong to your whole account, not only to the product whose page you are on. The section heading names the product only to say which sources are listed.

It has the same parts as the Configure window:

  • Taint sources, with Set all sources: which kinds of untrusted data every machine tracks. See Taint sources and Unset.
  • Other (es-python only): switches that sit with the taint sources but mark no data, such as identity and handoff. See Other.
  • Sent with each event (es-python only): command line, environment variables and source code. See Event context.
  • Suppressed events (es-python only): whether events EyalSec proved safe are kept or discarded. See Discard suppressed events.
  • Rules, with Apply template… and Save as template…: what happens to matching events on every machine. See Rules and Rule templates.

A machine's own taint setting overrides the global one; its own rules add to the global ones. See Machine settings and account settings.

The first time this section loads, your global rules start with two Don't send rules. See The rules every account starts with.

Product notes

When a product cannot act on everything the page offers, the note under the page description says what applies. The page only offers what the product can use: es-chromium has no taint sources and no Source column, and offers only Show and Hide rules.

Product What the note says, in short
es-python the argv, weak_random, hardcoded and identity controls do not change what it reports
es-chromium it does not fetch machine configuration, so everything here only filters the dashboard

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo