The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add time formats to Advanced Syslog Parser (ASP) rules

Prev Next

ASP parses most standard time formats, but you can add custom time formats so that they sync with the time formats of ASP logs.

  1. On the dashboard, click the Policy Editor icon GUID-D5AACD7D-9544-4011-8E37-D57FED1D7387-low.png.

  2. In the Rule Types pane, select the receiver, then click Advanced Syslog Parser.

  3. Select a rule, then click Edit → Modify.

  4. Select the Mapping tab, then click the plus icon above the Time Format table.

  5. Click in the Time Format field, then select the time format.

  6. Select the time fields that you want to use this format.

    Note

    First Time and Last Time see the first and last time the event is generated. Added Custom Type time fields also appear.

  7. Click OK, then complete the remaining information.