The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Modify a rule object

Prev Next

You can modify a rule object only at the admin domain where it was created. If required, you can clone a custom rule object that was created at a parent admin domain and then modify it as required in the current admin domain.

You cannot clone a default rule object except for Network. You cannot edit or delete any default rule object. You can edit or delete custom rule objects only at the admin domain where they were created.
  1. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Objects → Rule Objects.

    Rule objects for the selected admin domain are listed.

  2. Locate the rule object that you want to modify.

    To filter the list, select Custom Objects Only and select the corresponding rule object type from the object type drop-down.

  3. Make sure the Editable here field displays Yes for the rule object you want to modify. Then double-click the rule object.

    If the Editable here field displays No, the rule object belongs to a parent admin domain.

  4. Make the required changes and click Save.

    If the rule object that you modified is part of an ignore rule that is in use, you must do a configuration update to the Sensor for the changes to take effect.