The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

View Threat Intelligence Exchange execution history and set up actions

Prev Next

Trellix® Threat Intelligence Exchange (TIE) execution history displays systems that have executed the file associated with selected events.

A Trellix ePolicy Orchestrator - On-premises device with an attached Threat Intelligence Exchange server on Trellix ESM must exist.

  1. On the system navigation tree, click the Trellix ePolicy Orchestrator - On-premises device.

  2. On the Trellix ESM dashboard, select one or multiple Threat Intelligence Exchange events form the Events pane.

  3. In the Events pane, click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.pngActions TIE Execution History.

    Note

    On the TIE Execution History page, view the systems that have executed the Threat Intelligence Exchange file.

  4. To add this data to your workflow, select a system and click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png to:

    • Create watchlists

    • Append to watchlist

    • Create an alarm

    • Add to block list

    • Export to CSV