The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Set data source rule actions

Prev Next

Set the value of the event subtype per data source rule. Set default rule actions for dashboards, reports, parsing rules, or alarms.

  1. On the Trellix ESM console, click the Policy Editor icon GUID-D5AACD7D-9544-4011-8E37-D57FED1D7387-low.png, then select ReceiverData Source in the Rule Types pane.

  2. Click in the Subtype column for the rule you want to change, then select the new action.

    • Select enable to populate the event subtype with the default action, alert.

    • Select disable, if you don't want to collect events for the corresponding rule.

      Note

      Be careful when disabling rules. Events that match a disabled rule are not captured in Trellix ESM.

    • Select any other action to populate the event subtype with that action.