The rules table lists rules by rule type on two tabs: Trellix Rules and Customer Rules. When you first access the Rules page, rules on the Customer Rules tab are listed. You can search for rules in this table, filter them, and select one to view its details.
Filter the list of rules using the drop-down filters for the following attributes across the top of the tab:
Filter | Description |
|---|---|
Risk | Select a rule risk to see all of the rules with that risk. Selecting All will show you the rules for all risks in your environment. |
Rule Pack | Select a rule pack to see all of the rules that are a part of that rule pack. Selecting All will show you the rules for all rule packs in your environment. |
Status | Select Enabled to see all of the rules that have been enabled. Select Disabled to see all of the rules that have been disabled. Selecting All will show you both enabled and disabled rules. |
Assertions | Select Yes to see all of the rules with assertions. Select No to see all of the rules without assertions. Selecting All will show you the rules with and without assertions. |
Dependencies | Select Yes to see all of the rules with dependencies. Select No to see all of the rules without dependencies. Selecting All will show you the rules with and without dependencies. |
Alerting | Select Alerting to see all of the rules for which alerting is turned on. Select Not Alerting to see all of the rules for which alerting is turned off. Selecting All will show you all rules, regardless of alerting status. |
Covered | Select Yes to see all of the rules that are covered. Select No to see all the rules that are not covered. Selecting All will show you all rules, regardless of covered status. |
Tuned | This filter is only available on the Trellix Rules tab. Select Yes to see all of the Trellix rules that have been tuned. Select No to see all of the Trellix rules that have not been tuned. Selecting All will show you tuned and untuned Trellix rules. |
You can search existing rules by rule names, descriptions, and queries (the query used in the rule itself) using the Search field on the upper-right corner.
The following information is provided for each rule in the table.
Rule information | Description |
|---|---|
Risk | The risk to your environment when an event matches this rule. A single green dot indicates that the rule is low risk, two yellow dots indicate that the rule is medium risk, three orange dots indicate that the rule is high risk, and four red dots indicate that the rule is a critical risk. |
Name | The rule name. |
Rule Pack | The name of the rule pack that includes this rule. |
Distinguishers | The event fields that the rule uses to differentiate hits for the purpose of creating alerts. Typically, a distinguisher is a hostname or IP address, but it can be any event field. |
Query | The TQL query assigned to the rule. |
Tags | The tags assigned to the rule. |
Status | Whether the rule is enabled or disabled. |
Assertions | Number of assertions that are defined for the rule. |
Dependencies | Whether any dependencies have been defined for the rule. |
Alerting | Whether alerting has been turned on or off for the rule. |
Covered | This field appears on the Trellix Rules tab only. It indicates whether the data you are collecting includes data covered by the Trellix rule. If event data is received in a 24-hour period that has the minimum properties required by the Trellix rule, a Yes appears in this column for the rule. For example, if the rule checks for a specific |
Tuned | Whether the rule is tuned or not. |
Playbooks | The number of playbooks associated with the rule. |
Created At | The date the rule was created. |
Click the For Trellix rules, you can:
For customer rules, you can:
|
