The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure rule override actions

Prev Next

Rules can complete default actions when downloaded from the Trellix server. You can define an override action for the rule's default settings. If you do not define an override action, the rules take their default action.

  1. On the Policy Editor, click Tools → New Rule Configuration.

  2. Select the tags assigned to the rule where you want to apply this override. For example, to override the action for all filter rules with the AOL tag, click Current Threats → AOL in the tags list, then select Filter in the Rule Type field.

  3. Select the rule type to which you want this override applied.

  4. Select to have this rule and tag continue to use the default setting, to enable the override, or to disable this rule and tag.

  5. Select the severity for this override. Zero (0) is the default.

  6. Select Block List, Aggregation, or Copy Packet override settings, or keep the default settings.

  7. Click Close.