The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Increase accumulator indexes

Prev Next

Disable standard indexes to allow adding indexes to an accumulator field.

Due to the number of enabled standard indexes on Trellix ESM, you can add only 5 indexes to an accumulator field. If you need more than 5, you can disable up to 42 unused standard indexes (such as session ID, src/dst Mac, src/dst port, src/dst zone, src/dst geolocation).

Caution

Trellix ESM indexes all ports and MAC addresses by default and uses standard indexes to generate queries, reports, alarms, and views. If you disable an index, Trellix ESM notifies you when it can't generate a query, report, alarm, or view due to a disabled index, but it does not identify which index is disabled. Due to this limitation, do not disable standard indexes unless needed.

  1. From the Trellix ESM dashboard, click and select More Settings .

  2. Click Database.

  3. Click Settings, then click the Accumulator Indexing tab.

  4. From the Available list, click Standard Indexes, then select Show standard indexes.

  5. Click the standard indexes to be disabled, then click the arrow to move them to the Available area.

    7fTomThe number in the remaining statement in the top-right corner of the page increases with each standard index that you disable.

GUID-354F8E11-D566-4FEC-8992-EC9A5D3450C0You can now enable more than 5 accumulator indexes for the accumulator field that you select.