The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Set up correlation rules to compare event fields

Prev Next

Set up correlation rules to compare event fields (for example, compare that the source and destination user are the same). You can also set up a rule that ensures that the source IP address and destination IP address are different.

Note

The values used with the Regex, Does not match regex, Contains, and Does not contain operators can be case sensitive or case insensitive depending on the rules or Default correlation manager settings. For In/Not In operators, only random string watchlists can be evaluated as case-insensitive, based on the Default String Compare setting configured on the correlation manager.

  1. On the Trellix ESM console, click the Policy Editor icon GUID-D5AACD7D-9544-4011-8E37-D57FED1D7387-low.png.

  2. In the Rule Types pane, select Correlation, click the rule you want to compare fields in, then click EditModify

  3. Click the menu icon of a logic component Three_dots_icon.png, then click Edit.

  4. In the filters area, click Add, or select an existing filter and click Edit.

  5. Click the Default Value Editor icon GUID-911771E2-BC63-4466-BDB0-4D486C98E7FA-low.png, type the value and click Add, then select the field on the Fields tab and click Add.

    Numeric fields support the following operators: greater than (>), less than (<), greater than or equal to (>=), and less than or equal to (<=).