Viewing rule packs

Prev Next

You can view Trellix and customer rule packs on the Rule Packs page. The table on the page contains two tabs: one for Trellix Rule Packs and one for Customer Rule Packs.

To view the rule packs in your environment:

  • From the main menu, select Configure > Rule Packs.

The following information is provided for each rule pack in the rule pack table.

Rule pack information

Description

ID

The unique ID assigned to the rule pack when it was created.

Name

The name of the rule pack.

Coverage

This field appears on the Trellix Rule Packs tab only. It shows the percentage of rules within the rule pack for which you are collecting data. Two values are shown in this column:

  • A fraction. The numerator of the fraction shows the number of enabled Trellix rules in the rule pack that reference data classes that are currently sent in Helix Enterprise log data. The denominator of the fraction shows the total number of enabled Trellix rules in the rule pack.

  • The percentage resulting from the fraction.

For example, if 10 enabled Trellix rules are in a rule pack and 5 of them reference data that is currently collected and sent to Helix Enterprise, 50% of the rules have coverage. The following appears in the column for the rule pack: 5/10|50%.

Enabled

The number of rules within the rule pack that are enabled.

Disabled

The number of rules within the rule pack that are disabled.

Click kebab_icon.png in this column to perform an action on the rule pack.

For Trellix rule packs, you can:

  • Enable all the rules in the rule pack

  • Disable all the rules in the rule pack

For customer rule packs, you can:

  • Enabled all the rules in the rule pack

  • Disable all the rules in the rule pack

  • Export the rule pack to a JSON file

  • Delete the rule pack