The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

How Trellix Active Response searches work

Prev Next

Active Response offers continuous visibility and insights into your endpoints, so you can identify breaches as they happen. It helps security practitioners query the current security posture, improve threat detection, and perform detailed analysis and forensic investigations.

If Active Response is installed as an extension on ePO - On-prem devices added to Trellix ESM, you can use Active Response to search from the Trellix ESM. The search generates a list of current endpoint data, allowing you to:

  • View the list of search results

  • Create a watchlist populated with search results

  • Append Active Response search data to an existing watchlist

  • Add a data enrichment source populated with search results

  • Export search data

Note

Searching with Active Response uses Trellix® Data Exchange Layer.

When using Active Response on Trellix ESM note that:

  • High availability (HA) receivers do not support Trellix® Data Exchange Layer.

  • Date formats from an Active Response search are returned as 2018-11-05T23:10:14.263Z and not converted to the Trellix ESM date format.

  • When you append Active Response data to a watchlist, the system does not validate the data, which means you might add data to a watchlist that doesn't match its type.