The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create custom detection rules

Prev Next

Custom detection rules allow you to create rules to detect events specific to your needs.

To create a custom detection rule:

  1. On the Rules page, select Create New Rule.

  2. Enter a name and optional description, and select a severity from the menu.

  3. Write the rule condition. To ensure the rule will work, Helix validates the syntax as you type. It looks for errors in the YAML schema, validates datatypes, some regular expressions, for example within: 3h. It also validates the fields, correlation, cardinality, and deviation conditions. If there is an error, hover over the colored icon for more information. You cannot save a rule until all errors are fixed.

    Note

    Validation is not available for the match expression.

  4. (Optional) Add tags and select an exclusion list.

  5. Click Save.

The following table gives more information on each field of the custom detection rule.

Field

Description

Tenant ID

If you are a federated customer, select the tenant from the menu.

Name

Enter a name for the rule that briefly describes what it does. The name should be descriptive enough to find by scanning the Rules table.

Description

Provide a more detailed description of the rule, if desired.

Severity

Select a severity that matches the impact an alert triggered by this rule would have on your organization.

Condition

Enter the rule conditions. For more information, see Understanding the rule language.

Status

Enabled, Disabled, or Muted. Rules are enabled by default. Mute the rule to evaluate its performance over time, without showing alerts by default in the alert table.

Exclude these lists

A file containing a list of fields to exclude from the rule.

Tags

Select any tags that can categorize the rule.