The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Define order for ASP and filter rules

Prev Next

Set the order to run filter or Advanced Syslog Parser (AsP) rules so they generate the data you need.

Verify that you have policy administration privileges.

  1. On the Trellix ESM console, click the Policy Editor icon GUID-D5AACD7D-9544-4011-8E37-D57FED1D7387-low.png.

  2. On the Operations menu, select Order ASP Rules or Order Filter Rules, then select a data source in the Data source type field.

    Rules available to put into order appear on the left; ordered rules appear on the right.

  3. On the Standard Rules or Custom Rules tab, move a rule from the left to the right (drag and drop or use the arrows), placing them above or below Unordered Rules.

    Note

    Unordered Rules represent the rules in the left, which are those that are in default order.

  4. Use the arrows to reorder the rules, then click OK to save the changes.