The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Data source rules

Prev Next

A data source rule is a set of values of specific properties parsed from event logs. For each event, the parser creates a rule listing the signature ID, event message, normalization setting, sub-type, and severity. These rules are then populated in the Data Sources section of the Rule Types pane.

The Trellix Enterprise Security Manager - Event Receiver (SIEM Collector) auto learns data source rules as it processes the information sent to it by data sources.

The Data Source option in the Rule Types pane is only visible when you select a policy, data source, Advanced Syslog Parser, or SIEM Collector in the system navigation tree. The description area at the bottom of the page gives detailed information about the selected rule. All rules have a severity setting that dictates the priority associated with a rule, which impacts how the alerts generated for these rules are shown for reporting purposes.

Data source rules can be disabled and enabled.

Caution

Disabling rules prevents them from displaying anywhere in Trellix ESM. This can have unintended consequences.