The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix ESM rule types

Prev Next

Trellix ESM includes many types of rules that enable you to protect your environment.

  • Trellix Application Data Monitor rules -detect malicious traffic patterns by detecting anomalies in application and transport protocols.

  • Advanced Syslog Parser (ASP) rules - identify where data resides in message-specific events, such as signature IDs, IP addresses, ports, user names, and actions. ASP rules also create rule messages and populate custom fields for the data.

  • Correlation rules - interpret patterns in correlated data.

  • Data source rules - the values of specific properties parsed from event logs. For each event, the parser creates a rule listing the signature ID, event message, normalization setting, sub-type, and severity. These rules are then populated in the Data Sources section of the Rule Types pane.

  • Trellix ESM rules - generate compliance or auditing reports related to Trellix ESM events.

  • Filter rules - allow you to specify what action to take on Trellix Enterprise Security Manager - Event Receiver data.

  • Transaction tracking rules - track database transactions and auto-reconcile changes, such as log start and end of a trade execution or begin and commit statements to report by transactions instead of queries.

  • Windows events rules - events that are related to Windows.