The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Identify what triggered correlation rules

Prev Next

Identify what caused the rule to trigger and to tune for false positives.

  • Verify that you have administrator rights or belong to an access group with policy administration permission.

  • Verify that correlation data sources exist on Trellix ESM.

Details are always gathered at the time of request. But for rules that use dynamic watchlists or other values that might change often, set the rule to get details immediately after triggering. This reduces the chance that details are unavailable.

  1. From the dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png and select Correlation.

  2. Set rules to show details immediately.

    1. On the Trellix ESM console, click the Policy editor icon, then click Correlation in the Rule Types pane.

    2. Click the Details column for the rule and select On.

      You can select more than one rule at a time.

  3. View the details:

    1. On the system navigation tree, click Rule Correlation under the Trellix ESM - ACE device.

    2. From the view list, select Event ViewsEvent Analysis, then click the event you want to view.

    3. Click the Correlation Details tab to view the details.

    4. On the Event Analysis view, click the plus sign (+) in the first column next to the correlation event.

      Note

      A plus sign appears only if the correlation event has source events.