Use a sample log to test a new rule.
At least one sample log, in plain text format, must be available.
From the Trellix ESM dashboard, click and select More Settings .
In the navigation tree, select the data source, then click the Properties icon.
.png)
Click Upload.
Navigate to the log sample file and select it.
Click Upload.
Click Close.
Click Get Events and Flows.
Select Events then click Start.
Find the events in the dashboard and verify the newly created ASP rule is parsing as expected.