The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Watchlists

Prev Next

Filter information in your dashboard views and reports or as a condition that triggers correlation rules or alarms.

Hunting threats across large amounts of data can be easier if you use watchlists - lists of values (such as a list of malicious web sites) for filtering dashboard views, triggering correlation rules, configuring alarms, or similar activities.

Watchlists can be global or shared with specific users or groups. Watchlists can contain up to 1,000,000 values.

Watchlist workflow

  1. Configure Trellix ESM watchlists.

    • Static watchlists contain values (imported or entered manually) that don't change over time.

    • Dynamic watchlists contain values that change automatically, through queries, regular expressions, or string search criteria.

  2. Configure alarms and correlation rules that use watchlists as conditions.

  3. Filter dashboard views or reports using watchlists.

  4. Trigger alarms or correlation rules using watchlists as conditions.

    • Alarms can trigger any time events match values in the watchlist.

    • Correlation rules can use the watchlist condition to either trigger or prevent the rule from triggering.

GUID-EF19C85F-59C9-4B88-B75E-36C31D7020B5-low.png