The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Search using Trellix Active Response

Prev Next

Use Active Response to search for current endpoint data.

  • Add a ePO - On-prem device with Active Response to Trellix ESM.

  • In ePO - On-prem, make sure that Send Restrictions and Receive Restrictions are set to All Systems or have a tag that is also tagged on the receiver (Server SettingsTopic AuthorizationsActive Response Server API).

  1. Define search settings for the ePO - On-prem device.

    1. From the Trellix ESM dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png and select System properties.

    2. On the system navigation tree, select the device, then click Settings.png.

    3. Click Trellix ePO Properties, then click Connection.

    4. Select Enable DXL and specify an Agent Wake-up Port (default is 8081).

  2. On the Trellix ESM dashboard, select a view with a table widget, such as Event Analysis.

  3. Click an event, then click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png.

  4. Select ActionsExecute Active Response Search, then select a predefined search type.

    Note

    Search types are grayed out if the table doesn't have the appropriate fields for the search.

    • File details of the source and destination IP address, such as the operating system and name

    • User details

    • Source IP address process details for what established the connection

    • Destination IP address process details for what established the connection

    • Anyone connected to the same source or destination IP address