The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Set up correlation alarms to include source events

Prev Next

To include source events information in alarm results, set up an Internal Event Match or Field Match alarm that uses a correlation event as the match.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select Trellix ESM and click Settings.png.

  3. Click Alarms.

  4. Click the Settings tab and click Templates.

  5. On the Template Management page, click Add, then enter the information requested.

  6. In the Message Body section, place your cursor where you want to insert the tags, then click GUID-911771E2-BC63-4466-BDB0-4D486C98E7FA-low.png, and select Source Events Block.

  7. Place your cursor inside the tags, click GUID-911771E2-BC63-4466-BDB0-4D486C98E7FA-low.png, and select the information you want to include when the correlation alarm triggers.

The following example shows what an alarm message template looks like when you insert fields for an event's source IP address, destination IP address, and severity:

Alarm: [$Alarm Name]

Assignee: [$Alarm Assignee]

Trigger Date: [$Trigger Date]



Summary: [$Alarm Summary]



[$REPEAT_START]

Correlation SigID: [$Signature ID]

Correlated Last Time: [$Last Time]



[$SOURCE_EVENTS_START] 

Source Event Details: 



Last Time: [$Last Time] 

SigID: [$Signature ID]

Rule Message: [$Rule Message]

Severity: [$Average Severity]



Src User: [$%UserIDSrc]

Src IP: [$Source IP]

Src Port: [$Source Port]



Dst User: [$%UserIDDst]

Dst IP: [$Destination IP]

Dst Port: [$Destination Port] 



Host: [$%HostID]

Command: [$%CommandID]

Application: [$%AppID]

Packet: [$Packet Data]



[$SOURCE_EVENTS_END]

[$REPEAT_END]

Note

If a correlated event does not trigger the alarm, the message does not include the data.