The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Set data source rule actions

Prev Next

Set the value of the event subtype per data source rule. Set default rule actions for dashboards, reports, parsing rules, or alarms.

  1. On the Trellix ESM console, click the Policy Editor icon GUID-D5AACD7D-9544-4011-8E37-D57FED1D7387-low.png, then select Receiver → Data Source in the Rule Types pane.

  2. Click in the Subtype column for the rule you want to change, then select the new action.

    • Select enable to populate the event subtype with the default action, alert.

    • Select disable, if you don't want to collect events for the corresponding rule.

      Note

      Be careful when disabling rules. Events that match a disabled rule are not captured in Trellix ESM.

    • Select any other action to populate the event subtype with that action.