Trellix ESM includes many types of rules that enable you to protect your environment.
Trellix Application Data Monitor rules -detect malicious traffic patterns by detecting anomalies in application and transport protocols.
Advanced Syslog Parser (ASP) rules - identify where data resides in message-specific events, such as signature IDs, IP addresses, ports, user names, and actions. ASP rules also create rule messages and populate custom fields for the data.
Correlation rules - interpret patterns in correlated data.
Data source rules - the values of specific properties parsed from event logs. For each event, the parser creates a rule listing the signature ID, event message, normalization setting, sub-type, and severity. These rules are then populated in the Data Sources section of the Rule Types pane.
Trellix ESM rules - generate compliance or auditing reports related to Trellix ESM events.
Filter rules - allow you to specify what action to take on Trellix Enterprise Security Manager - Event Receiver data.
Transaction tracking rules - track database transactions and auto-reconcile changes, such as log start and end of a trade execution or begin and commit statements to report by transactions instead of queries.
Windows events rules - events that are related to Windows.