The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Uploading custom rules using the Web UI

Prev Next

Use the Custom Rules page to upload a custom rule file to the appliance or sensor.

NX_CustomRules_Scap.png

Each time a new file containing custom rules is uploaded, all previous rules are overwritten. For information about custom rule file usage, requirements, and the keywords supported by the Network Security, see Creating custom rule limitations.

To see the results of new custom rules, provide unique names, such as CompanyX.Zbot. This name or a portion of it can be used to filter the hits your appliance or sensor is detecting. At the Alerts or Summaries tab Search box, enter your filter term (for example, CompanyX).

To upload a custom rule file:

  1. In the Web UI, choose Settings > Custom Rules.

  2. To select a local custom rule file, click Choose File.

    File names can include the following characters: letters (a-z, A-Z), numbers (0-9), underscores (_), periods (.), plus and minus signs (+, -), single quotes (‘), and left and right parentheses. Any other characters are replaced with the minus (-) sign. For example, if the name of the file you upload is hello%hello.doc, then it will be renamed and stored on the appliance or sensor as hello-hello.doc.

  3. (Optional) In the Description field, enter a text description.

  4. To upload and activate the rule file, click Update.

    The rules are activated and displayed on the Custom Rules page.

    NX_CustomRules_File_Scap.jpg

  5. To view a description of the errors in the file, click Download Log.

    If there are any format or syntax errors in your rules file, none of the rules in the file are loaded. Existing custom rules continue to be active when a file upload fails. Fix the errors and reload the rules file.

    NX_CustomRules_Error_Scap.jpg

  6. To delete a Custom Rule file, click Delete File.

Creating custom rule limitations

Custom rules must be legal rules.

Note

Not all options are supported now. Send feedback about the options available, or requests to support additional configurations in future releases, to csportal.fireeye.com.

Blocking

If an appliance or sensor is deployed inline, rules can be configured to block traffic. The drop keyword can be used in place of the alert keyword.

Variables

The $HOME_NET variable is configured with the homenet command. The default is "any".

The $PROXY_PORTS variable limits alerts based on the source or destination IP addresses existing on a predefined network. This variable is configured with the web-analysis ports command. This variable defines the ports at which the appliance or sensor will receive standard Web traffic. The default value is 80,8080. If your Web traffic is on a different port because of a network proxy server, set this variable to the proxy port using the web-analysis ports command, and then include that port designation as the destination port in your custom rules.

Other host and port variables can be created and used in the same file that contains the custom rules.

Limitations

In addition to enforcing standard syntax, the following limitations are set:

SID Range

The range for the SID is from 900000 to 999999.

msg field

The msg field contains only the name of the signature to be reported in the Web UI. This field has a maximum of 64 alphanumeric characters, dots, underscores, and hyphens.

Keywords

A subset of the available keywords is listed in the following table.

ack

dsize

id

pass

sid

alert

fastpattern

ipopts

pcre

threshold

ans1

flags

ip_proto

priority

tos

byte_jump

flowbits

isdataat

rawbytes

ttl

byte_test

fragbits

itype

reference

window

content

fragoffset

metadata

rev

within

depth

ftpbounce

msg

rpc

distance

icmp_id

nocase

sameip

drop

icode

offset

seq

Priority

The Network Security uses priorities to control the order of processing. The default is the lowest priority. A priority of over 100 must be assigned to make sure that a particular rule always starts before any others.

Traffic

The Network Security runs multiple signature-less Multivector Virtual Execution (MVX) engines to detect the latest threats. HTTP- and IRC-based traffic is the type of traffic primarily sent, so custom signatures for HTTP and IRC need to be deployed.

Performance

Custom signatures can affect the overall performance of the appliance or sensor and reduce the processing power available for dynamic threat detection. If possible, specify IP addresses and ports instead of using the default $HOME_NET variable “any.” Avoid rules that start too frequently, and rules that require evaluation of complex regular expressions.