The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Add Risk Correlation manager

Prev Next

Add risk correlation manager to enhance threat detection with dynamic risk scores and real-time activity tracking, enabling effective risk analysis and response.

  • Verify that Trellix ESM - ACE or Trellix Enterprise Security Manager - Enterprise Log Manager devices exist on Trellix ESM.

  • Make sure that storage pools exist on the Trellix Enterprise Security Manager - Enterprise Log Manager.

  • Make sure zones exist.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select Trellix ESM - ACEand click Settings.png.

  3. Select Correlation Management and click Add.

  4. In the manager type, select Risk Correlation.

  5. On the Main tab, enter the manager name and enable it.

    • Trellix ESM collects both event and flow data.

      Indicate whether to send event or flow data to the Trellix ESM - ACE device (the default is to send event data only).

    • Select Enable ELM Logging to save the logs on the Trellix Enterprise Security Manager - Enterprise Log Manager. Identify the storage pool on the Trellix Enterprise Security Manager - Enterprise Log Manager where you want the system to save the logs.

    • If you want the data to be assigned to a zone, select it from the drop-down list.

  6. On the Fields tab, select the fields that this manager uses to correlate events (maximum of 5 per manager).

    • Select the percentage to apply to each field, totaling 100 percent.

      Note

      Risk updates, when below 100 percent critical, report their criticality in terms of what you have defined as FYI, Minor, Warning, Major, and Critical (see Thresholds tab). For example, if your concept of FYI = 50% of the critical value when the risk = 50% of critical, the severity = 20 rather than 50.

    • Select if you don't want a field to be used to determine uniqueness. Avoid correlating against multiple high cardinality fields due to high memory requirements.

      Note

      The number of risk lines generated depends on the number of unique combinations of all correlated fields.

  7. On the Thresholds tab, set the score thresholds for an event to trigger for each criticality level. Set the rate for the score to decay. Default - for every 120 seconds that a score is in a bucket, it decays by 10 percent until it reaches a score of 5. The bucket for the unique field values is then deleted.

  8. On the Filters tab, use logic elements and components to set up filters.

  9. Click Finish, then click Write to write the managers to the device.