The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Add time formats to Advanced Syslog Parser (ASP) rules

Prev Next

ASP parses most standard time formats, but you can add custom time formats so that they sync with the time formats of ASP logs.

  1. On the dashboard, click the Policy Editor icon GUID-D5AACD7D-9544-4011-8E37-D57FED1D7387-low.png.

  2. In the Rule Types pane, select the receiver, then click Advanced Syslog Parser.

  3. Select a rule, then click EditModify.

  4. Select the Mapping tab, then click the plus icon above the Time Format table.

  5. Click in the Time Format field, then select the time format.

  6. Select the time fields that you want to use this format.

    Note

    First Time and Last Time see the first and last time the event is generated. Added Custom Type time fields also appear.

  7. Click OK, then complete the remaining information.