The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Create custom types

Prev Next

Add custom types to use as filters.

Verify that you have administrator rights or belong to an access group with user management permissions.

If you have administrator privileges, you see predefined custom types on System PropertiesCustom Types.

  1. From the Trellix ESM dashboard, click and select More Settings .

  2. From the Trellix ESM dashboard, click and select More Settings .

  3. Click Custom Types.

  4. Click Add:

    • Select a data type from the drop-down list.

      • Time - Seconds Precision stores time data down to the second.

      • Time - Nanosecond Precision stores time down to the nanosecond. It includes a floating-point number with 9 precision values representing the nanoseconds.

      • If you select Index when adding this custom type, the field shows up as a filter on queries, views, and filters. It doesn't appear in distribution components and isn't available in data enrichment, watchlists, or alarms.

    • Select the custom type's slot for each event or flow.

    • To filter by this custom type, select Index Data, which adds the custom type to the list of filters available for views, reports, and rules. The custom type doesn't appear in distribution components and isn't available in data enrichment, watch lists, or alarms. If you don't select this option, you can only filter this custom type with a regular expression.

    • If you select Long Custom or Short Custom in the Data Type field, you can add custom subtypes.

      • Number of Subtypes — Select the number of subtypes that you want to add to the table.

      • Name column — Click each subtype, then type a name.

      • Data Type column — Click each subtype, then select the data type for each subtype.

        Note

        If you select Boolean, validation ensures that they appear in groups of 8 subtypes.

      • Length column — If you selected Integer or Unsigned Integer in the Data Type column, select the data length in bytes. An integer's length must be 1, 2, 4, or 8.

      • Manage Indexing — If you selected Accumulator Value in the Data Type field, click to enable indexes for each accumulator field.

    • If you select the Name/Value Group data type, add the value pairs names in the text field.