The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Conflicts when importing correlation rules

Prev Next

Exporting correlation rules creates a file with the rule data. But, the file does not include referenced items such as variables, zones, watchlists, custom types, and assets, which this rule might use.

You might encounter import errors if you import a file with referenced rule items that don't exist on the importing system. For example, if rule 1 references variable $abc, and no variable is defined on the importing system that is named $abc, this condition flags the rule as in conflict.

To avoid conflicts, create the needed referenced items (manually or through import where applicable) or change the correlation rule and rule references.

Immediately after the import the system lists which rules are in conflict (flagged with an exclamation point !) or which failed. You can view and change the rule conflict details from this list.