The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Logic elements

Prev Next

When you add a Trellix Application Data Monitor device, database, and correlation rule or component, use Expression Logic or Correlation Logic to build the rule's framework.

Element

Description

AND

Functions the same as a logical operator in a computer language. Everything that is grouped under this logical element must be true for the condition to be true. Use this option if you want all conditions under this logical element to be met before a rule is triggered.

OR

Functions the same as a logical operator in a computer language. Only one condition grouped under this element has to be true for this condition to be true. Use this element if you want only one condition to be met before the rule is triggered.

SET

For correlation rules or components, SET allows you to define conditions and select how many conditions must be true to trigger the rule.

Each of these elements has a menu with at least two of these options:

  • Edit — You can edit the default settings.

  • Remove logical element — You can delete the selected logical element. If it has any children, they aren't deleted and move up in the hierarchy.

    Note

    This doesn't apply to the root element (the first one in the hierarchy). If you remove the root element, all children are also removed.

  • Remove logical element and all of its children — You can delete the selected element and all its children from the hierarchy.

When you set up the rule's logic, you must add components to define the conditions for the rule. For correlation rules, you can also add parameters to control the behavior of the rule or component when it executes.