By default, customer rules are enabled when they are created. In addition, the Trellix detection team attempts to maintain a set of default enabled rules that are universally applicable to most customers. However, customer networks and detection strategies are very diverse, meaning these rules won’t always be “one size fits all.”
In some cases, a rule may not be able to be tuned properly for certain environments or it just may not be applicable altogether. If a rule is producing lots of false positive alerts, you may decide to disable it. You can also enable or disable all the rules in a rules pack.
Individual rules can be enabled and disabled on the Rules page. You can also enable and disable customer rules when you edit them.
To enable any rule from the Rules page:
From the main menu, select Configure > Rules.
Locate the rule on the Trellix Rules or the Customer Rules tab.
Click
at the end of the row for the rule. Select Enable.
To enable a customer rule while editing it:
From the main menu, select Configure > Rules.
Select the Customer Rules tab.
Click on the name of the rule you want to edit, or select View / Edit from the Options menu. The Rule window will appear.
Click the Edit (
) icon in the upper right corner of the Rule window.Set the Enable Rule toggle to ON in the Update Rule window.
Click Update Rule.
To disable any rule from the Rules page:
From the main menu, select Configure > Rules.
Locate the rule on the Trellix Rules or the Customer Rules tab.
Click
at the end of the row for the rule. Select Disable.
To disable a customer rule while editing it:
From the main menu, select Configure > Rules.
Select the Customer Rules tab.
Click on the name of the rule you want to edit, or select View / Edit from the Options menu. The Rule window will appear.
Click the Edit (
) icon in the upper right corner of the Rule window.Set the Enable Rule toggle to OFF in the Update Rule window.
Click Update Rule.