The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Import/Export watchlists

Prev Next

Share static watchlist values with multiple Trellix ESM devices in your organization by importing and exporting the watchlists.

  • Verify that you have administrator rights or belong to an access group with watchlist permissions.

    Without these privileges, you cannot edit, export, or remove private watchlists or watchlists that contain strings or rules names.

  • You must have a Trellix GTI license to export watchlists that contain GTI Malicious IPs and GTI Suspicious IPs values.

  1. From the Trellix ESM dashboard, click menu.png and select Watchlists.

  2. Click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png to list active and inactive watchlists.

  3. Export a watchlist.

    1. Select an existing watchlist and click Export.

      Note

      You cannot export Trellix GTI watchlists.

    2. Browse to the location where you want to export the watchlist file.

    3. Click Confirm.

  4. Import a watchlist.

    1. Select Import.

    2. Browse to the location of the watchlist file you want to import.

    3. Click Confirm.