The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Historical correlation

Prev Next

Use historical correlation to correlate past events.

When the system discovers a new vulnerability, check your historical events and logs to determine whether your organization was exploited in the past. Replay historical events using the Risk Correlation rule-less correlation engine and the standard rule-based event correlation engine.

Examine historical events against today's threat landscape in these situations:

  • Correlation was not set up during the time certain events triggered; correlating those events can reveal valuable information.

  • Set up new correlation based on past triggered events and test the new correlation to confirm results.

Be aware of the following when using historical correlation:

  • Real-time correlation cannot run until you disable historical correlation.

  • Event aggregation skews risk distribution.

  • When you move the Risk Manager back to real-time risk correlation, tune the thresholds.

To set up and run historical correlation, you must:

  1. Add a historical correlation filter.

  2. Run a historical correlation.

  3. Download and view the correlated historical events.