The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Virtual devices

Prev Next

Use virtual devices to monitor traffic, compare traffic patterns, and for reporting.

Purpose and benefits

Use virtual devices to:

  • Compare traffic patterns against rule sets. For example, set up virtual devices to look at web traffic ports and set up policoes where you can enable or disable different rules.

  • Reporting. Using it in this manner is like having an automatic filter set up.

  • Monitor multiple paths of traffic at once. By using a virtual device, you can have separate policies for each path of traffic and sort different traffic into different policies.

The number of virtual devices that you can add to a Trellix Application Data Monitor varies by the model.

How Trellix ESM uses selection rules

Trellix ESM uses selection rules as filters to determine the packets that a virtual device processes.

For a packet to match a selection rule, all filter criteria defined by that rule must be matched. If the packet’s information matches all filter criteria for a single selection rule, the virtual device that contains the matching selection rule processes it. Otherwise, it is passed on to the next virtual device in order. The Trellix Application Data Monitor itself then processes it, as a default, if no selection rules are matched on any virtual devices.

Things to note for IPv4 virtual devices:

  • The system sorts all packets for a single connection based only on the first packet in the connection. If the first packet in a connection matches a selection rule for the third virtual device in the list, all subsequent packets in that connection go to the third virtual device. This happens even if the packets match a virtual device that is higher in the list.

  • The system sorts invalid packets (a packet that is not setting up a connection or part of an established connection) to the base device. For example, you have a virtual device that looks for packets with a source or destination port of 80. When an invalid packet comes through with a port of 80, the system sorts it to the base device instead of the virtual device that looks for port 80 traffic. So, you see events in the base device that look like they should have gone to a virtual device.

The order that the system lists selection rules matters, because the first time a packet matches a rule, the system automatically routes that packet to that virtual device for processing. For example, you add four selection rules and the fourth one in order is the filter that triggers most often. This means each packet must pass over the other filters for this virtual device before getting to the most commonly triggered selection rule. To enhance the efficiency of the processing, make the most commonly triggered filter first in order, instead of last.

Order of virtual devices

The system compares packets coming into the Trellix Application Data Monitor to the selection rules for each virtual device in the order that the virtual devices are set up. So, the order in which the system checks virtual devices matters. The packet makes it to the selection rules for the second virtual device only if it doesn't match any selection rules on the first device.

Trellix Application Data Monitor virtual devices

Trellix Application Data Monitor virtual devices monitor traffic on an interface. There can be up to four Trellix Application Data Monitor interface filters on your system. Each filter can be applied to only one virtual device at a time. If a filter is assigned to a Trellix Application Data Monitor virtual device, it does not appear on the list of available filters until it is removed from that device.