The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Filter views

Prev Next

Filters help you view details about selected items on a view. If you enter filters and refresh the view, the data in the view reflects the filters you added.

  1. On the Trellix ESM console, select the view you want to filter.

  2. In the Filter pane, filter your view in one of the following ways:

    • Type the filter information in the appropriate field. For example, to filter the view to see only the data that has a source IP address of 161.122.15.13, type the IP address in the Source IP field.

    • Type a contains or regex filter.

    • Click the Display filter list icon GUID-C4056A30-9E8D-4DC5-832C-5E1D6B4C9461-low.png next to the field and select the variables or watchlists to filter on.

    • On the view, select the data you want to use as the filter, then click the field on the Filter pane. If the field is blank, it is auto-populated with the data you selected.

    Note

    For Average Severity, use a colon (:) to enter a range. For example, 60:80 is a severity range of 60–80.

  3. Specify how to filter the data in your view.

    • Include or exclude data from the view.

    • Use regular and OR filters.

      Note

      At least 2 fields must be selected OR for this filter to work.

    • To filter data by case, click GUID-517C33F3-35F8-4318-80DE-4260A469952C-low.png.

    • To replace normalized strings with their aliases, click GUID-D273ECF1-06D8-440C-A0A6-82A0BD77D87F-low.png.

  4. To run the query, click GUID-9E27FAD7-66B6-444F-A303-6A2D91FAFBD1-low.png.

Trellix ESM refreshes the view. An orange filter icon appears in the upper-right corner of the view pane, indicating that the data in the view is a result of filters. If you click the icon, the system removes the filters and the view shows all data.