Search for indicator rules and conditions

Prev Next

You can search for indicator rules and conditions using the Endpoint Security (HX) Web UI. You cannot search for them using the CLI.

Prerequisites
  • Admin, Senior Analyst, or Investigator access

To search for indicator rules and conditions:
  1. Log in to the Endpoint Security (HX) Web UI.

  2. Select Rules from the Configure section of the main menu to access the Rules page.

  3. Select the Indicators tab.

  4. In the Search by name, created by, signature, or condition box, enter one of the following:

    • Name—the indicator rule name

    • Created by—the user name or other identification of the source of the indicator rule. Trellix-supplied indicator rules usually have source names that start with "General."

    • Signature—a value provided by other Trellix products

    • Condition value—the value of the condition, such as the MD5 hash value or filename

  5. Click the magnifying glass on the right side of the search box or press Enter.

    The list of indicator rules on the Indicator tab is filtered for only the indicator rules that match your search criteria.