This chart shows the percentage of enabled Trellix rules that are covered for the last 14 days. A rule is covered if at least one event is received in a 24 hour period that has the minimum properties that the rule requires in order to allow the rule query to be run against it.

Use the information in this widget to see how many Trellix rules have been enabled in your environment and to determine how well the classes and metaclasses of log data you are sending to Helix Enterprise match those referenced in enabled Trellix rules.
Data sent to your environment for class types that are not explicitly referenced in enabled Trellix rules is uncovered data. Data sent to your environment for class types that are explicitly referenced in enabled Trellix rules is covered data.
Use this information to maximize your use of Trellix rules with respect to your contractual EPS.