The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Define order for ASP and filter rules

Prev Next

Set the order to run filter or Advanced Syslog Parser (AsP) rules so they generate the data you need.

Verify that you have policy administration privileges.

  1. On the Trellix ESM console, click the Policy Editor icon GUID-D5AACD7D-9544-4011-8E37-D57FED1D7387-low.png.

  2. On the Operations menu, select Order ASP Rules or Order Filter Rules, then select a data source in the Data source type field.

    Rules available to put into order appear on the left; ordered rules appear on the right.

  3. On the Standard Rules or Custom Rules tab, move a rule from the left to the right (drag and drop or use the arrows), placing them above or below Unordered Rules.

    Note

    Unordered Rules represent the rules in the left, which are those that are in default order.

  4. Use the arrows to reorder the rules, then click OK to save the changes.