The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Flow views

Prev Next

A flow is a record of a connection made between an asset on your network and another device. When flow analysis is enabled, data is recorded about each flow, or connection.

Flows have source and destination IP addresses, ports, MAC addresses, a protocol, and a first and last time (indicating duration between the start and finish of the connection).

Because flows are not an indication of anomalous or malicious traffic, there are more flows than events. A flow is not associated with a rule signature (SigID) like an event. Flows are not associated with event actions such as Alert, Drop, and Reject.

Certain data is unique to flows, including source and destination bytes and source and destination packets. Source bytes and packets indicate the number of bytes and packets transmitted by the flow's source. The destination bytes and packets indicate the number of bytes and packets transmitted by the flow's destination.

Flows have a direction, and the source of the flow defines the direction.

  • Flows generated by Trellix ESM:

    • An inbound flow originates from outside the HOME_NET.

    • An outbound flow originates from inside the HOME_NET.

  • Flows generated by a third party:

    • The third party supplying the data defines the direction of the inbound and outbound flow.

To view flow data, you must enable your system to log flow data. You can then view flows on the Flow Analysis view.