The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Manage rules

Prev Next

ADM, Deep Packet Inspection, Advanced Syslog Parser, and Correlation rules can be viewed, copied, and pasted. Custom rules of these types can be modified or deleted. Standard rules can be modified, but must be saved as a new custom rule.

  1. In the Rule Types pane of the Policy Editor, select the type of rule that you want to work with.

  2. To view custom rules:

    1. Select the Filter tab in the Filters/Tagging pane.

    2. At the bottom of the pane, click the Advanced bar.

    3. If you want to view a Generic - Advanced Syslog Parser rule, clear the Device Type ID field.

    4. In the Origin field, select user defined, then click Run Query GUID-9E27FAD7-66B6-444F-A303-6A2D91FAFBD1-low.png.

  3. To copy and paste a rule:

    1. Select a predefined or custom rule.

    2. Select EditCopy, then select EditPaste.

      The rule you copied is added to the list of existing rules, with the same name and settings.

      Note

      For ASP and Filter Rules, the rule order is copied as part of the copy process.

    3. Check that the ordering of the new rule will not adversely affect data parsing (OperationsOrder ASP Rules) or (OperationsOrder Filter Rules).

    4. To change the name, select EditModify.

  4. To modify a rule:

    1. Highlight the rule you want to view, then select EditModify.

    2. Change the settings, then click OK. If it's a custom rule, it's saved with the changes. If it is a standard rule, you are prompted to save the changes as a new custom rule. Click Yes.

      Note

      If you did not change the name of the rule, it is saved with the same name and a different sigID.

    3. You can change the name by selecting the rule, then selecting EditModify.