The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Correlation

Prev Next

Identify and score threat events in real time, using both rule- and risk-based logic.

Some activities on your network appear benign when viewed in isolation, but become suspicious when viewed in a larger context of multiple related activities. Use correlation to look across multiple events and flows to detect patterns that indicate a larger threat.

You can set up Configure Trellix ESM - ACE using real-time or historical modes:

Correlation can be performed in real time for immediate risk analysis and in historical mode to reexamine older activities to find occurrence of risks not understood then (such as zero-day attacks).

  • Real-time mode — analyzes events as they are collected for immediate threat and risk detection.

  • Historical mode — replays available data collected through either or both correlation engines for historical threat and risk detection. When Trellix ESM - ACE discovers new zero-day attacks, it determines whether your organization was exposed to that attack in the past.

Trellix ESM - ACE devices supplement the existing event correlation capabilities for Trellix ESM by providing two dedicated correlation engines. Configure each Trellix ESM - ACE device with its own policy, connection, event and log retrieval settings, and risk managers.

  • Risk correlation — generates a risk score using rule-less correlation. Rule-based correlation only detects known threat patterns, requiring constant signature tuning and updates to be effective. Rule-less correlation replaces detection signatures with a one-time configuration: Identify what is important to your business (such as a particular service or application, a group of users, or specific types of data). Risk correlation then tracks all activity related to those items, building a dynamic risk score that raises or lowers based on real-time activity.

    When a risk score exceeds a certain threshold, Trellix ESM - ACE generates an event and alerts you to growing threat conditions. Or, the traditional rule-based correlation engine can use the event as a condition of a larger incident. Trellix ESM - ACE maintains a complete audit trail of risk scores for full analysis and investigation of threat conditions over time.

  • Rule-based correlation — detects threats using traditional rule-based event correlation to analyze collected information in real time. Trellix ESM - ACE correlates all logs, events, and network flows with contextual information, such as identity, roles, vulnerabilities, and more—to detect patterns indicative of a larger threat.

    Trellix Enterprise Security Manager - Event Receivers support network-wide, rule-based correlation. Trellix ESM - ACE complements this capability with a dedicated processing resource that correlates larger volumes of data, either supplementing existing correlation reports or off-loading them completely.