The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Trellix ESM rule types

Prev Next

Trellix ESM includes many types of rules that enable you to protect your environment.

  • Trellix Application Data Monitor rules -detect malicious traffic patterns by detecting anomalies in application and transport protocols.

  • Advanced Syslog Parser (ASP) rules - identify where data resides in message-specific events, such as signature IDs, IP addresses, ports, user names, and actions. ASP rules also create rule messages and populate custom fields for the data.

  • Correlation rules - interpret patterns in correlated data.

  • Data source rules - the values of specific properties parsed from event logs. For each event, the parser creates a rule listing the signature ID, event message, normalization setting, sub-type, and severity. These rules are then populated in the Data Sources section of the Rule Types pane.

  • Trellix ESM rules - generate compliance or auditing reports related to Trellix ESM events.

  • Filter rules - allow you to specify what action to take on Trellix Enterprise Security Manager - Event Receiver data.

  • Transaction tracking rules - track database transactions and auto-reconcile changes, such as log start and end of a trade execution or begin and commit statements to report by transactions instead of queries.

  • Windows events rules - events that are related to Windows.