Set data source rule actions Published on Sep 12, 2026
Print
Copy page Copy as Markdown for LLMs View as Markdown View the page as plain text
Open in ChatGPT Ask ChatGPT about this page Open in Claude Ask Claude about this page Prev Next Set the value of the event subtype per data source rule. Set default rule actions for dashboards, reports, parsing rules, or alarms.
On the Trellix ESM console, click the Policy Editor icon , then select → in the Rule Types pane.
Click in the Subtype column for the rule you want to change, then select the new action.
Select enable to populate the event subtype with the default action, alert .
Select disable , if you don't want to collect events for the corresponding rule.
Note Be careful when disabling rules. Events that match a disabled rule are not captured in Trellix ESM .
Select any other action to populate the event subtype with that action.
Was this article helpful?
Yes No
Related articles
Enterprise Security Manager > Enterprise Security Manager 11.7.x > ESM 11.7.x Product Guide > Defining policies and rules > Rules > Trellix ESM rule types > Data source rules
Enterprise Security Manager > Enterprise Security Manager 11.7.x > ESM 11.7.x Installation Guide > Deploy a Trellix ESM solution on a VM > Add and configure devices > Configure receivers
Enterprise Security Manager > Enterprise Security Manager 11.6.x > ESM 11.6.x Installation Guide > Deploy a Trellix ESM solution on a VM > Add and configure devices > Configure receivers