The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Add exceptions to event aggregation settings

Prev Next

Aggregation settings apply to all events generated by a device. You can create exceptions for individual rules if the general settings don't apply to the events generated by that rule.

  1. On the views pane, select an event generated by the rule you want to add an exception for.

  2. Click the Menu icon GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png, then select Modify Aggregation Settings.

  3. Select the field types you want to aggregate from the Field 2 and Field 3 drop-down lists.

    Important

    The fields you select in Field 2 and Field 3 must be different types or an error results. When you select these field types, the description for each aggregation level changes to reflect the selections you made. The time limits for each level depend on the event aggregation setting you defined for the device.

  4. Click OK to save your settings, then click Yes to continue.

  5. Deselect devices if you do not want to roll out the changes to them.

  6. Click OK to roll out the changes to the devices that are selected.

The Status column shows the status of the update as the changes are rolled out.