The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Rule management best practices

Prev Next

Use the following suggestions to write a well-defined rule:

  • Avoid writing queries that are too broad. The more focused your query, the fewer matches per second it will generate. If you are trying to detect behavior that requires a broad query, then try to limit the number of fields you group by in the rule.

  • Avoid choosing fields that can result in a random distribution of their values. If there are large numbers of unique combinations (500,000+), performance can be greatly impacted.

  • Limit the number of fields you group by for each individual rule. This is critical when writing rules that generate assertions, but do not generate alerts. Note that if a rule is generating only assertions, then you most likely do not need to use the groupby parameter at all.

  • Limit the window on rules that do generate alerts to one minute for as many alerting rules as possible.

  • Limit the Threshold value. Unless it is critical for the rule to function, it is best to leave the threshold as low as possible to minimize the number of overall matches.

For example, the following rule uses a broad query, multiple groupby fields, a large window, and a large threshold:

  • Search: metaclass:[http_proxy,firewall,connection]

  • Groupby: srcipv4, dstipv4, srcport, dstport

  • Window: 1 day

  • Threshold: 10

This rule can be dramatically improved by narrowing its scope:

  • Search: metaclass:[http_proxy,firewall,connection] srcipv4:153.251.53.0/24 srcport:80

  • Groupby: srcipv4

  • Window: 1 minute

  • Threshold: 1