The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Variables

Prev Next

There can be some values that you may need to mention in all or most of the rules. For example, the target subnet could be the same for many rules. Instead of repeating it in each rule, you can define a variable for the subnet, and then use the variable in the rules. The advantage with using variables is when you want to modify the value. For example, if the target subnet is now different, then instead of modifying each rule, you can just redefine the variable with the new value.

You can use variables for the following:

  • Path to a file: When you import Snort rules from a file, you can include other files from within the file that you are importing. Then rules from all these files are automatically imported. When you include a file within another file, you need to provide the absolute or the relative path to the file being referenced. Alternatively, you can use a variable for the path and mention it instead of the mentioning the path to the file.

  • IP addresses: You can use variables for the source and target IP addresses or subnets.

  • Port numbers: You can use variables for the source and target port numbers.