The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Modify a custom rule object

Prev Next

You can modify custom rule objects.

  • You cannot modify or delete a default rule object.

  • You can modify or delete a custom rule object only at the admin domain where it was created. If required, you can clone a custom rule object that was created at a parent admin domain and then modify it as required in the current admin domain.

  • You cannot clone a default rule object except for Network. You cannot edit or delete any default rule object. You can edit or delete custom rule objects only at the admin domain where they were created.

Note

Options differ depending on the rule object type you select. For information on a specific object type, refer to the corresponding sub-section.

  1. Click the Policy tab.

  2. From the Domain drop-down list, select the domain you want to work in.

  3. Select Intrusion Prevention → Objects → Rule Objects.

    Rule Objects for the selected admin domain are listed.

  4. Locate the rule object that you want to modify.

    • You can use the search function to easily find the rule object.

    • Make sure the Editable here column displays Yes for the rule object you want to modify. If the Editable column displays No, the rule object belongs to a parent admin domain.

  5. Double-click the rule object.

  6. Make the required changes and click Save.

    Note

    If the rule object that you modified is part of a policy that is in use, you must do a configuration update to the Sensor for the changes to take effect.