The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Rule coverage trend widget (Legacy)

Prev Next

This chart shows the percentage of enabled Trellix rules that are covered for the last 14 days. A rule is covered if at least one event is received in a 24 hour period that has the minimum properties that the rule requires in order to allow the rule query to be run against it.

Helix_RuleCoverageTrend.png

Use the information in this widget to see how many Trellix rules have been enabled in your environment and to determine how well the classes and metaclasses of log data you are sending to Trellix Helix match those referenced in enabled Trellix rules.

Data sent to your environment for class types that are not explicitly referenced in enabled Trellix rules is uncovered data. Data sent to your environment for class types that are explicitly referenced in enabled Trellix rules is covered data.

Note

The uncovered data you are collecting may still be useful for Trellix rules that do not reference a class type or for custom rules you have added to your environment.

Use this information to maximize your use of Trellix rules with respect to your contractual BPS.