---
title: "Configuring ETL Filters"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35365862/Configuring%20ETL%20Filters"
format: markdown
---
Data Connector ETL filters are used to exclude specific information. Using filter expressions from flow configuration page, you can send or drop specific information. After configuring an ETL filter to exclude specific information, you can apply the filter to your traffic flow configuration. The data that has not been excluded or removed will be transferred to the configured destinations. To set up ETL filters, use regexes (regular expressions) for Grid member names and for IP/Network, FQDN, DNS Record Type, OPHID, and ON-PREM HOST.

The following wildcards are supported:

| **Wildcard** | **Description** | **Example** |
| --- | --- | --- |
| * | Applicable to one or more domain name labels. It can be specified only on the left side of the domain name. | *.foo.com |
| # | Applicable to one or more labels for a domain name. Can be specified only on the left side of a domain name. | #./foo.com |
| ? | Used to specify exactly one label for a domain name. Can be specified on the left or right side of the domain name. | ?.foo.com<br>?, ?.<br>corp.?.<br>test.? |

> ⚠️ **Note**
> ⚠️ 
> ⚠️ - For **Threat Class/Property**, the supported ETL data filters are processed in the following order: **client_ip, member**, **query FQDN**, ** DNS record type**, and** Threat Class/Property.**
> ⚠️ - Data Connector automatically filters out NIOS log messages received from Infoblox Platform. In the past, they were sent to Infoblox Platform by Data Connector.

> ℹ️ The stated information is  for reference only. It represents the results of lab testing in a controlled environment focused on individual protocol services. Enabling additional protocols, services, cache hit ratio for recursive DNS, and customer environment variables will affect performance. To design and size a solution for a production environment, please contact your Infoblox Solution Architect.

The following details of ETL filters are supported for log types of source data:

| ## **ETL filters supported for source data log types** |
| --- |
| ### **Source** | ### **Log Type** | ### **FQDN** | ### **Client IP/Network ** | ### **Member** | ### **DNS Record Type** | ### **Ophid** | ### **Hostname** | ### **Threatclass/Property** |
| ### **Infoblox Source** | Threat Defense Query/Response Log | Yes | Yes | <span style="color: #4d5156">—</span> | Yes | Yes | Yes | <span style="color: #4d5156">—</span> |
| Threat Defense Threat Feeds Hits Log | Yes | Yes | <span style="color: #4d5156">—</span> | Yes | Yes | Yes | <span style="color: #4d5156">Yes</span> |
| DDI Query/Response Log | Yes | Yes | <span style="color: #4d5156">—</span> | Yes | Yes | Yes | <span style="color: #4d5156">—</span> |
| DDI DHCP Lease Log | <span style="color: #4d5156">—</span> | Yes | <span style="color: #4d5156">—</span> | <span style="color: #4d5156">—</span> | <span style="color: #4d5156">—</span> | Yes | <span style="color: #4d5156">—</span> |
| ### **NIOS Source** | Query/Response Log | Yes | Yes | Yes | Yes | <span style="color: #4d5156">—</span> | <span style="color: #4d5156">—</span> | <span style="color: #4d5156">—</span> |
| IPAM Metadata/DHCP Lease Information | <span style="color: #4d5156">—</span> | Yes | <span style="color: #4d5156">—</span> |  | <span style="color: #4d5156">—</span> | <span style="color: #4d5156">—</span> | <span style="color: #4d5156">—</span> |
| RPZ Logs | Yes | Yes | Yes | Yes | <span style="color: #4d5156">—</span> | <span style="color: #4d5156">—</span> | <span style="color: #4d5156">—</span> |

You must configure the NIOS appliance to send syslog messages to an external Data Connector over TCP. By default, the NIOS appliance sends these messages over UDP.

> ⚠️ **Advisory**
> ⚠️ 
> ⚠️ The NIOS UI provides a mechanism for filtering the domain names it sends to Cloud Data Connector. Because NIOS sends cache logs, when configuring NIOS for use with Cloud Data Connector, make sure to configure Cloud Data Connector to exclude internal corporate and authoritative domains: ***.<corp domains> **and** *.<Authoritative Zones>**. If you exclude corporate and authoritative domains, internal traffic logs will not be added. The complete list of domains to be excluded is listed *below *<span style="color: #172b4d">as a downloadable test file. </span>  
> ⚠️   
> ⚠️   
> ⚠️ 
> ⚠️ 
> ⚠️ Note that the domains recommended for exclusion can be applied as an ETL filter on Cloud Data Connector or as a list of excluded domains on NIOS.
> ⚠️ 
> ⚠️ > Macro (inline-media-image)
> ⚠️ 
> ⚠️   
> ⚠️ **Image**: <span style="color: #0d0d0d">The configuration panel from NIOS, specifically for setting up DNS properties in relation to a Data Connector.</span>
> ⚠️ 
> ⚠️ 
> ⚠️ For more details, see *[Setting Up the NIOS Grid](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35464209)*.

To view all ETL configurations, do the following:

> Macro (legacy-content)

## ETL Configuration

In the details panel located to the right of the page, you can view the ETL configuration. Click the information icon to open/close the panel.

## Filters

Click the filter icon to open the filter options panel. ETL configuration filters can be applied based on *Name*, *Data Type*, *Description*, and *State*. 

## Search

Use the search functionality (search box) to conduct a local search based on ETL criterion. 


For more information on ETL configurations, see the following:

> Macro (children)