The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure custom rules

Prev Next

Configure Trellix Application Data Monitor, database, or correlation rules, using logical and regular expressions or predefined rules as templates.

  1. From the dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png and select Policy Editor.

  2. View existing custom rules:

    1. Select the Filters/TaggingFilter tab.

    2. Click the Advanced bar at the bottom.

    3. In the Origin field, select user-defined.

    4. Click Run Query.

  3. Click New, then configure database and correlation rules:

    • Identify the rule name, description (that appears in the Policy Editor), a severity setting, and rule type.

    • Select the alert action the rule triggers.

    • Change the default normalized ID.

    • Select tags that define the categories to which the rule belongs.

    • To set rule logic, drag and drop the wanted logical elements and components.

  4. Define values that events must match to trigger a correlation rule:

    • Apply filters to event data, flow data, or both.

    • To select if a specific number of values must occur in a specific field before the component triggers, click GUID-911771E2-BC63-4466-BDB0-4D486C98E7FA-low.png .

      • Distinct Values — Select the number of values that must occur.

      • Monitored field — Select the field that the values must occur in.

    • Select to have the component trigger only if matches do not occur in the time specified in the Time Window field at the gate level.

    • Select to customize the grouping of the events in a correlation rule. If you have a rule that groups by a specific field, you can override one of its components to match on a field that you specify on the Configure Group By overrides page. Click Configure to set the override field.

  5. Define expression component settings:

    • Select to exclude the values you select.

    • Select the metric reference for this expression.

    • Type a component description.

    • If you want this rule to reference a Trellix Application Data Monitor dictionary on Trellix ESM, select it on the drop-down list.

    • Select the relational operator.

      Trellix Application Data Monitor:

      • Equal to =

      • Not equal to !=

      • Greater than >

      • Greater than equal to >=

      • Less than equal to <=

      • Less than <

    • Select whether the rule triggers when any of the values match the defined pattern, or only if all values match the pattern.

    • Filter by selected variables:

      • If the variables icon is next to the field, click it and select the variables.

      • If there is no icon, type the value following the instructions in the Valid Input field.

    • View hints for the values that you can enter in the Value field.