Aggregating events generates a list of events grouped and consolidated by the selected criteria. You can then create exclusions using the information from specific events.
Select Menu → Reporting → Exploit Prevention Events.
In the System Tree, select the groups to show events for.
If needed, select Actions → Choose Columns, then add or remove columns from the display.
The displayed columns determine the criteria that you can aggregate events on. By default, the Exploit Prevention Events page displays these columns from the Exploit Prevention Events queries and reports data:
API Name
Action Taken
Analyzer Rule ID (also known as the Signature ID)
Detecting Product Host Name
Target Hash
Target Signer
Threat Name
Threat Target File Path
The columns that you select are associated with your user ID and persist when you log off from Trellix ePO - On-prem. To remove custom columns, click Use Default on the Select Columns to Display page.
Click Aggregate, select the columns to aggregate events on, then click OK.
The aggregated view consolidates the events by the selected criteria (columns) and lists the number of events for each.
For example, to aggregate events by signer, select the Target Signer column. The aggregation shows the number of events associated with each signer. You can then use this information to create exclusions for files from a specific trusted signer.
Click a row to display the events that match the criteria.
From this page, you can select events for creating exclusions.
Click Close to return to the aggregated events view.
Click Clear to remove aggregation settings.
The previous list of Exploit Prevention events appears.