The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

How filters work

Prev Next

In the filters pane, add and delete filter fields, save filter sets, change the default set, manage all filters, and start the string normalization manager. Any filters that are applied to a view are carried forward to the next view that is opened.

When you first log on to Trellix ESM, the default filters pane includes the Source User, Destination User, Source IP, and Destination IP filter fields.

An orange funnel icon appears in the upper-right corner of the view pane indicates that filters are applied to the view. Click the orange icon to clear filters and execute the query again.

Anywhere you have comma-separated filter values such as variables, global filters, local filters, normalized strings, or report filters, you must use quotes if they are not part of a watchlist. If the value is Smith,John, you must type "Smith,John". If there are quotes in the value, you must enclose the quotes in quotes. If the value is Smith,"Boy"John, you must enter it as "Smith,""Boy""John".

Note

You can use contains and regex filters.