Filter Content Rules

The Filters panel allows you to filter the list of displayed contents under the content library based on the name, medium, date range, and source type.

This applies to the following content rule types:

  • Feed

  • Application Rule

  • Log Device

  • Lua Parser

  • Network Rule

  • Event Steam Analysis Rule

  • Bundle

To filter the content rules

  1. Go to netwitness_configure.png (CONFIGURE) > Policies.
  2. In the policies panel, click Content.
  3. Click Content Library.

  4. By default, the filters panel is hidden, click the netwitness_displayfilter.png (Filters) icon in the toolbar to expand the filters panel.


  5. To search by policy name:

    • Set the filter option to Contains operator from the drop-down list and start typing the name of the policy. Type one character and a list of policies that contain that character is displayed, as you continue to type the list is filtered to match.

    • Set the filter option to Equals operator from the drop-down list and enter the full name. The particular content type will be displayed.

  6. To filter by medium, select one or more mediums from the Medium drop-down list. The options are listed below:

    • endpoint

    • log

    • log and packet

    • packet

  7. To filter by date range, under the Last Update date, select the start date and end date from the date fields.

    For example, to filter policies that were updated between July 1 and July 30, you select July 1 as the start date and July 30 as the end date. You must enter dates in mm/dd/yyyy format or you click and pick dates from a calendar.

  8. To filter by source type, select one or more sources from the Source Type drop-down list. The options are listed below:

    • Custom

    • Live

  9. To hide, click the netwitness_hidefilter.png icon at the top-right of the panel.

    The contents are displayed in the right panel according to the filter you selected. Click Reset to clear the existing filter results.