The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Add Rule Correlation manager

Prev Next

Add rule correlation manager to enhance threat detection through real-time analysis, pattern identification, and proactive security monitoring.

  • Verify that Trellix ESM - ACE or Trellix Enterprise Security Manager - Enterprise Log Manager devices exist on Trellix ESM.

  • Make sure that storage pools exist on the Trellix Enterprise Security Manager - Enterprise Log Manager.

  • Make sure zones exist.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select Trellix ESM - ACEand click Settings.png.

  3. Select Correlation Management and click Add.

  4. In the manager type, select Rule Correlation.

  5. On the Main tab, enter the manager name and enable it.

    • Trellix ESM collects both event and flow data.

      Indicate whether to send event or flow data to the Trellix ESM - ACE device (the default is to send event data only).

    • Select Enable ELM Logging to save the logs on the Trellix Enterprise Security Manager - Enterprise Log Manager. Identify the storage pool on the Trellix Enterprise Security Manager - Enterprise Log Manager where you want the system to save the logs.

    • If you want the data to be assigned to a zone, select it from the drop-down list.

    • Select the amount of time that the rule correlation allows for events to be out of order. For example, if you set up 60 minutes, the system can use an event that is 59 minutes late.

    • Select Case Sensitive or Case Insensitive from the Default String Compare drop-down list.

      Note

      Case Sensitive is the default global setting in the rule correlation manager.

  6. On the Filters tab, use logic elements and components to set up filters.

  7. Click Finish, then click Write to write the managers to the device.