The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Aggregate Exploit Prevention events

Prev Next

Aggregating events generates a list of events grouped and consolidated by the selected criteria. You can then create exclusions using the information from specific events.

Task
  1. Select MenuReportingExploit Prevention Events.

  2. In the System Tree, select the groups to show events for.

  3. If needed, select ActionsChoose Columns, then add or remove columns from the display.

    The displayed columns determine the criteria that you can aggregate events on. By default, the Exploit Prevention Events page displays these columns from the Exploit Prevention Events queries and reports data:

    API Name

    Action Taken

    Analyzer Rule ID (also known as the Signature ID)

    Detecting Product Host Name

    Target Hash

    Target Signer

    Threat Name

    Threat Target File Path

    The columns that you select are associated with your user ID and persist when you log off from Trellix ePO - On-prem. To remove custom columns, click Use Default on the Select Columns to Display page.

  4. Click Aggregate, select the columns to aggregate events on, then click OK.

    The aggregated view consolidates the events by the selected criteria (columns) and lists the number of events for each.

    For example, to aggregate events by signer, select the Target Signer column. The aggregation shows the number of events associated with each signer. You can then use this information to create exclusions for files from a specific trusted signer.

  5. Click a row to display the events that match the criteria.

    From this page, you can select events for creating exclusions.

    Click Close to return to the aggregated events view.

  6. Click Clear to remove aggregation settings.

    The previous list of Exploit Prevention events appears.