Editing Trellix rules

Prev Next

Rule tuning allows you to modify or adjust Trellix rules.

Tip

For help with understanding TQL and its syntax, see the TQL Reference Guide.

To tune a Trellix rule:
  1. In the Trellix Rules tab of the Rules page, click on the name of a Trellix rule.

  2. Click the Tune Query button.

  3. Enter a TQL query in the Tuned Query Field, such as "NOT srcipv4=1.2.3.4"

  4. Adjust the threshold and interval as needed.

  5. Click Save. The new values will be appended to the original query.

Note

The modified query parameters override the original query parameters.

To edit a tuned Trellix query:
  1. In the Trellix Rules tab of the Rules page, click on the name of a tuned Trellix rule.

  2. Click the Edit Tuned Query button.

  3. Modify the TQL query, threshold, and interval as needed.

  4. Click Save.