Rules table

Prev Next

The rules table lists rules by rule type on two tabs: Trellix Rules and Customer Rules. When you first access the Rules page, rules on the Customer Rules tab are listed. You can search for rules in this table, filter them, and select one to view its details.

Filter the list of rules using the drop-down filters for the following attributes across the top of the tab:

Filter

Description

Risk

Select a rule risk to see all of the rules with that risk. Selecting All will show you the rules for all risks in your environment.

Rule Pack

Select a rule pack to see all of the rules that are a part of that rule pack. Selecting All will show you the rules for all rule packs in your environment.

Status

Select Enabled to see all of the rules that have been enabled. Select Disabled to see all of the rules that have been disabled. Selecting All will show you both enabled and disabled rules.

Assertions

Select Yes to see all of the rules with assertions. Select No to see all of the rules without assertions. Selecting All will show you the rules with and without assertions.

Dependencies

Select Yes to see all of the rules with dependencies. Select No to see all of the rules without dependencies. Selecting All will show you the rules with and without dependencies.

Alerting

Select Alerting to see all of the rules for which alerting is turned on. Select Not Alerting to see all of the rules for which alerting is turned off. Selecting All will show you all rules, regardless of alerting status.

Covered

Select Yes to see all of the rules that are covered. Select No to see all the rules that are not covered. Selecting All will show you all rules, regardless of covered status.

Tuned

This filter is only available on the Trellix Rules tab.

Select Yes to see all of the Trellix rules that have been tuned. Select No to see all of the Trellix rules that have not been tuned. Selecting All will show you tuned and untuned Trellix rules.

You can search existing rules by rule names, descriptions, and queries (the query used in the rule itself) using the Search field on the upper-right corner.

The following information is provided for each rule in the table.

Rule information

Description

Risk

The risk to your environment when an event matches this rule. A single green dot indicates that the rule is low risk, two yellow dots indicate that the rule is medium risk, three orange dots indicate that the rule is high risk, and four red dots indicate that the rule is a critical risk.

Name

The rule name.

Rule Pack

The name of the rule pack that includes this rule.

Distinguishers

The event fields that the rule uses to differentiate hits for the purpose of creating alerts. Typically, a distinguisher is a hostname or IP address, but it can be any event field.

Query

The TQL query assigned to the rule.

Tags

The tags assigned to the rule.

Status

Whether the rule is enabled or disabled.

Assertions

Number of assertions that are defined for the rule.

Dependencies

Whether any dependencies have been defined for the rule.

Alerting

Whether alerting has been turned on or off for the rule.

Covered

This field appears on the Trellix Rules tab only.

It indicates whether the data you are collecting includes data covered by the Trellix rule. If event data is received in a 24-hour period that has the minimum properties required by the Trellix rule, a Yes appears in this column for the rule.

For example, if the rule checks for a specific dstipv4 value and event data is sent that includes the dstipv4 property (even if the specific value of the dstipv4 property does not match the value in the rule), this column will contain a Yes.

Tuned

Whether the rule is tuned or not.

Playbooks

The number of playbooks associated with the rule.

Created At

The date the rule was created.

Click the kebab_icon.png icon in this column to perform an action on the rule.

For Trellix rules, you can:

  • View the rule

  • Disable the rule

For customer rules, you can:

  • View and edit the rule

  • Disable the rule

  • Export the rule

  • Delete the rule