The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Creating a multistage rule (Legacy)

Prev Next

To create a rule in a multistage rule:

  1. From the main menu, select Configure > Rules.

  2. Click Create Rule. The Create Rule dialog appears.

  3. Supply the following information on the Create Rule dialog:

  4. Click Advanced at the bottom of the Create Rule dialog.

  5. Create assertions and dependencies, as appropriate for the stage of the rule in the multistage rule. See Multistage rule workflow and Assertions and dependencies.

    • If this is a first-stage rule, it must have at least one assertion, but no dependencies.

    • If this is a middle-stage rule, it must have at least one assertion and at least one dependency.

    • If this is a final-stage rule, it must have at least one dependency and no assertions.

    See Assertions and Dependencies.

  6. After appropriate assertions and dependencies have been defined, click Create Rule. The rule is saved.

Important

When the multistage rule is satisfied, a class=analytics application='multi-stage rules' event is created.

If you want to generate alerts for the multistage rule, you must create another rule that matches on this analytics event. For example, if the final-stage rule has a rule ID of 9999.0.1, the query for the alerting multistage rule would be:

class=analytics application='multi-stage rules' detect_ruleids:9999.0.1