A data source rule is a set of values of specific properties parsed from event logs. For each event, the parser creates a rule listing the signature ID, event message, normalization setting, sub-type, and severity. These rules are then populated in the Data Sources section of the Rule Types pane.
The Trellix Enterprise Security Manager - Event Receiver (SIEM Collector) auto learns data source rules as it processes the information sent to it by data sources.
The Data Source option in the Rule Types pane is only visible when you select a policy, data source, Advanced Syslog Parser, or SIEM Collector in the system navigation tree. The description area at the bottom of the page gives detailed information about the selected rule. All rules have a severity setting that dictates the priority associated with a rule, which impacts how the alerts generated for these rules are shown for reporting purposes.
Data source rules can be disabled and enabled.
Caution
Disabling rules prevents them from displaying anywhere in Trellix ESM. This can have unintended consequences.