The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Add SOAR playbooks to Trellix ESM

Prev Next

You can add the SOAR playbooks to Trellix ESM to execute the events and enable the Trellix Security Orchestrator to respond to the incidents.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select Trellix ESM and click Settings.png.

  3. From System Properties, click SOAR Integration.

  4. Select SOAR Playbook and click Add.

  5. In the Name option, enter a name for the SOAR playbook.

  6. In the Endpoint Name option, select an endpoint.

  7. In the External Playbook Name option, select a playbook.

    Note

    The Description field is optional.

  8. To map the event field to the playbook parameters:

    1. Click GUID-911771E2-BC63-4466-BDB0-4D486C98E7FA-low.png and select Event FieldsNetwork Destination IP.GUID-8BE991C3-7435-4A7A-B720-41150F87773E-low.png

    2. Click OK.

      Note

      Map the event field based on the playbook parameters.

  9. Select Permission and enable the required permission for the users and groups, then click OK.GUID-10E51665-8426-4852-A315-12A2A830D8A8-low.png