The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Management of rule objects

Prev Next

You can use rule objects to create ignore rules. You can use common rule objects across other features in the Manager such as Firewall.

Rule objects, in ignore rules, can be customized to override any settings made at the parent domain level. They can be customized at the admin domain level, child domain level or the Sensor level.

Note

The ability to customize a rule object is only available for ignore rules. Firewall, which also uses rule objects, does not support rule object customization.

Icon/Option

Definition

Rule object

Displays the rule objects according to the filter criteria. Click a column heading to sort the table in ascending or descending order.

  • Name — Indicates the name of the rule objects.

  • Description — Indicates the description of the rule object.

  • Type — Indicates the rule object type.

  • Owner Domain — Indicates the admin domain to which a rule object belongs. All the default rule objects belong to the root admin domain.

  • Visibility — Indicates the visibility settings of settings to the domains, whether it is visible only to the owner domain or to both owner and child domains.

  • Editable here — Yes indicates that the rule object is a custom rule object belonging to the current admin domain. If it is No, you cannot edit the rule object because it is a default rule object or a custom rule object defined at a parent admin domain.

Object Type

Filters rule objects in the list.

  • Default Objects Only — Trellix pre-defined these rule objects. For example, the Application and Country are default rule objects. You cannot define these rule objects.

  • Custom Objects Only — You need to define these rule objects. For example, you need to define the Host DNS Name rule object.

  • Custom and Default Object — When selected, it displays both the predefined and user-defined rule objects. For example, IPv4 Network Rule Object has the 3 reserved private networks pre-defined, but you can create your Network rule objects as well.

Rule Object Type

Select the rule object type that you want to view.

Search

Type your search criteria in the field to find rule objects with matching elements. For example, type

to list the rule objects containing google as part of their names.

GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png

icon

Creates a custom rule object.

GUID-717A81EC-A913-4C2F-B61C-0129ED30387A-low.png

icon

Clones a rule object. You cannot clone default rule objects other than the IPv4 network rule objects.

GUID-9A719AD5-F6BE-4CD4-9311-CC6655DF9B70-low.png

icon

Deletes a custom rule object belonging to the current admin domain.

To view or edit a rule object

Double-click the rule object belonging to the current admin domain.

The following table lists the available rule objects and the corresponding icons.

Icon

Rule Object

GUID-A020136A-CC09-4EF7-93DE-EF44D7A29378-low.png

IPv4 Endpoint

GUID-A020136A-CC09-4EF7-93DE-EF44D7A29378-low.png

IPv6 Endpoint

GUID-78F07A0F-F120-43C3-AC52-2477A874EBEE-low.png

IPv4 Address Range

GUID-78F07A0F-F120-43C3-AC52-2477A874EBEE-low.png

IPv6 Address Range

GUID-54A52AA8-1967-4856-90E2-B844AA571B05-low.png

Network Group for ignore rule

GUID-0BC6CFE7-DD84-439E-A44E-7AD06E222447-low.png

IPv4 Network

GUID-0BC6CFE7-DD84-439E-A44E-7AD06E222447-low.png

IPv6 Network

Note

IPv6 Address Range and Network Group for Ignore Rule are two new types of rule objects that are only applicable to ignore rules.

By default, a Sensor inherits the rule object definitions from the domain that owns the Sensor (when the rule object is not customized at the Sensor level). If there is no customized definition present in this domain, the Sensor inherits the object definition from its parent domains in the hierarchy until a valid definition is found.

You can customize rule object definitions at the child domain level, only if the resources belong to the child domain. Such changes, made at the child domain level, will be visible in the parent admin domain level and can also be modified here.

If you delegate an interface (say G0/1) belonging to a Sensor to a child domain, all the rule objects assigned to that interface (through ignore rules) inherit their definition from the customization at the physical Sensor level. If there is no Sensor level definition, the specific rule object inherits its definition from the admin domain to which the Sensor belongs.