The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Enterprise Security Manager - Application Data Monitor rule metric references

Prev Next

Use the following metric references when adding Trellix Application Data Monitor rules.

For Common Properties and Common Anomalies, the parameter-type value you can enter for each one is shown in parentheses after the metric reference.

Common Properties

Property or term

Description

Protocol (Number)

The application protocol (HTTP, FTP, SMTP)

Object Content (String)

The content of an object (text inside a document, email message, chat message). Content matching is not available for binary data. Binary objects can, but, be detected using Object Type (objtype)

Object Type (Number)

Specifies the type of the content as determined by Trellix Application Data Monitor (Office Documents, Messages, Videos, Audio, Images, Archives, Executables)

Object Size (Number)

Size of the object. Numeric multipliers K, M, G can be added after the number (10K, 10M, 10G)

Object Hash (String)

The hash of the content (currently MD5)

Object Source IP address (Number)

The source IP address of the content. IP address can be specified as 192.168.1.1, 192.168.1.0/24, 192.168.1.0/255.255.255.0

Object Destination IP address (Number)

The destination IP address of the content. IP address can be specified as, 192.168.1.1, 192.168.1.0/24, 192.168.1.0/255.255.255.0

Object Source Port (Number)

The source TCP/UDP port of the content

Object Destination Port (Number)

The destination TCP/UDP port of the content

Object Source IP address v6 Address (Number)

The source IPv6 address of the content

Object Destination IPv6 Address (Number)

The destination IPv6 address of the content

Object Source MAC Address (Mac name)

The source MAC address of the content (aa:bb:cc:dd:ee:ff)

Object Destination MAC Address (Mac name)

The destination MAC address of the content (aa:bb:cc:dd:ee:ff)

Flow Source IP address (IPv4)

Source IP address of the flow. IP address can be specified as 192.168.1.1, 192.168.1.0/24, 192.168.1.0/255.255.255.0

Flow Destination IP address (IPv4)

Destination IP address of the flow. IP address can be specified as 192.168.1.1, 192.168.1.0/24, 192.168.1.0/255.255.255.0

Flow Source Port (Number)

Source TCP/UDP port of flow

Flow Destination Port (Number)

Destination TCP/UDP port of flow

Flow Source IPv6 Address (Number)

Source IPv6 address of the flow

Flow Destination IPv6 Address (Number)

Destination IPv6 address of the flow

Flow Source MAC Address (Mac name)

Source MAC address of the flow

Flow Destination MAC Address (Mac name)

Destination MAC address of flow

VLAN (Number)

Virtual LAN ID

Day of Week (Number)

The day of the week. Valid values are 1–7; 1 is Monday.

Hour of Day (Number)

The hour of the day set to GMT. Valid values are 0–23.

Declared Content Type (String)

Type of the content as specified by the server. In theory, Object Type (objtype) is always the actual type and Declared Content-type (content-type) is not trustworthy because it can be spoofed by the server/application.

Password (String)

Password used by the application for authentication.

URL (String)

Website URL. Applies only to HTTP protocol.

File Name (String)

Name of the file being transferred.

Display Name (String)

Host Name (String)

Host name as specified in DNS lookup.

Common Anomalies

  • User logged off (Boolean)

  • Authorization error (Boolean)

  • Authorization successful (Boolean)

  • Authorization failed (Boolean)