The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling custom YARA rules using the CLI

Prev Next

Use the commands in this procedure to enable or disable custom YARA rules on your Network Security appliance. You cannot use the Web UI to configure YARA rules.

Note

You cannot configure YARA rules using the sensor CLI.

Prerequisites

  • An established connection between the Network Security appliance and the Internet.

  • Administrator or Operator access to the Network Security appliance.

To enable custom YARA rules:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enable the custom YARA rules.

    hostname (config) # yara policy cust
  3. Verify your configuration.

    hostname (config) # show static-analysis config
    .....
    Yara Configuration
     Yara policy                             : cust
    .....
  4. Save your changes.

    hostname (config) # write memory
To disable custom YARA rules:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Disable the custom YARA rules.

    hostname (config) # yara policy disable
  3. Verify your configuration.

    hostname (config) # show static-analysis config
    .....
    Yara Configuration
      Yara policy                             : disable
  4. Save your changes.

    hostname (config) # write memory