View Threat Intelligence Exchange execution history and set up actions Published on Sep 12, 2026
Print
Copy page Copy as Markdown for LLMs View as Markdown View the page as plain text
Open in ChatGPT Ask ChatGPT about this page Open in Claude Ask Claude about this page Prev Next Trellix ® Threat Intelligence Exchange (TIE) execution history displays systems that have executed the file associated with selected events.
A Trellix ePolicy Orchestrator - On-premises device with an attached Threat Intelligence Exchange server on Trellix ESM must exist.
On the system navigation tree, click the Trellix ePolicy Orchestrator - On-premises device.
On the Trellix ESM dashboard, select one or multiple Threat Intelligence Exchange events form the Events pane.
In the Events pane, click → → .
Note On the TIE Execution History page, view the systems that have executed the Threat Intelligence Exchange file.
To add this data to your workflow, select a system and click to:
Create watchlists
Append to watchlist
Create an alarm
Add to block list
Export to CSV
Was this article helpful?
Yes No
Related articles
Enterprise Security Manager > Enterprise Security Manager 11.7.x > ESM 11.7.x Product Guide > PG - ESM - Tuning McAfee ESM > Tuning your ESM configuration > ePO - On-prem as a device > TrellixThreat Intelligence Exchange integration
Endpoint Security (ENS) > ENS 26.x > Trellix Endpoint Security (ENS) 26.x - Web Control Product Guide - macOS > Managing the software with Trellix ePO - On-prem and Trellix ePO - SaaS > Adaptive Threat Protection policy
Endpoint Security (ENS) > ENS 26.x > Trellix Endpoint Security (ENS) 26.x - Threat Prevention Product Guide - macOS > Managing the software with Trellix ePO - On-prem and Trellix ePO - SaaS > Adaptive Threat Protection policy