The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Filter existing rules

Prev Next

Filter existing rules to view only those that meet your criteria. By default, rules of a specific type appear in the Policy Editor in alphabetical order. You can list them by time or use tags to filter the rules.

Note

Double quotation marks are the default delimiter for ASP rules. If you use a double quote in a filter rule, add a backslash before it so that it is recognized as part of the search string.

  1. In the Rule Types pane of the Policy Editor, select the type of rule you want to filter.

  2. Select the Filter tab in the Filters/Tagging pane.

  3. Do any of the following:

    • Filter with multiple tags by selecting categories or tags, then click the Run Query icon GUID-9E27FAD7-66B6-444F-A303-6A2D91FAFBD1-low.png.

    • Select more than one category or tag, then click the or icon, then click the Run Query icon.

      Note

      You can't use the or icon to filter fields affected by inheritance (Action, Severity, Block List, Aggregation, and Copy Packet).

    • Type the tag's name in the Type here to search for a tag field, then select the one you need from the list of options.

    • List the rules by the time they were created by clicking the Sort on Time icon GUID-5B745946-EA2F-41CE-B610-652E1A78B890-low.png on the toolbar, then click the Run Query icon.

    • List the rules in alphabetical order by clicking the Sort on Name icon GUID-6214CAA0-1641-4A54-9542-A125C1B0C105-low.pngon the toolbar, then click the Run Query icon.

    • Deselect the filtering by clicking the orange filter icon on the rules display pane title bar GUID-CD0E9334-78CA-4329-83BC-6976CEF7E1E6-low.png.

    • Deselect the filter tags by clicking the Clear All icon GUID-89DDBDA2-3625-42CE-8D73-87CF5F43330B-low.png on the toolbar. The tags are deselected but the list of rules remains filtered.

    • Filter by signature ID by clicking the Advanced bar at the bottom of the Filter pane. Then, type the signature ID, then click the Run Query icon.

    • Filter by name or description. In the Advanced pane, enter the name or description. For the results, regardless of case, click the case-insensitive icon GUID-517C33F3-35F8-4318-80DE-4260A469952C-low.png.

    • Filter by device type, normalized ID, or action. In the Advanced pane, click the Filter icon GUID-C4056A30-9E8D-4DC5-832C-5E1D6B4C9461-low.png. On the Filter Variables page, select the variable.

    • Compare the differences in the policy-based settings for a rule type and its immediate primary. In the Advanced pane, select View Exceptions, then click the Run Query icon.

    • Filter by severity, block list, aggregation, copy packet, origin, and rule status by selecting the filter from the drop-down list in each of these fields.

    • View only custom rules by selecting user-defined in the Origin field in the Advanced pane, then click the Run Query icon.

    • View rules created in a specific time period by clicking the calendar icon next to the Time field on the Advanced pane. On the Custom Time page, select the start and stop time, click OK, then click the Run Query icon.