The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Enable Copy Packet for rules

Prev Next

When you enable Copy Packet for a rule, the system copies the packet data Trellix ESM. If enabled, packet data is included in the source event data of an Internal Event Match or Field Match alarm.

  1. On the console, click the Policy Editor icon GUID-D5AACD7D-9544-4011-8E37-D57FED1D7387-low.png.

  2. In the Rule Types pane, click the rule type that you want to access, then locate the rule in the rule display pane.

  3. Click the current setting in the Copy Packet column, which is off by default, then click on.