Rules can complete default actions when downloaded from the Trellix server. You can define an override action for the rule's default settings. If you do not define an override action, the rules take their default action.
On the Policy Editor, click → .
Select the tags assigned to the rule where you want to apply this override. For example, to override the action for all filter rules with the AOL tag, click → in the tags list, then select Filter in the Rule Type field.
Select the rule type to which you want this override applied.
Select to have this rule and tag continue to use the default setting, to enable the override, or to disable this rule and tag.
Select the severity for this override. Zero (0) is the default.
Select Block List, Aggregation, or Copy Packet override settings, or keep the default settings.
Click Close.