The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure custom attributes

Prev Next

As a user with the required permissions, you can create, edit, or remove user-related or incident-related custom attributes. Some examples of custom attributes are user's Manager information, Employee ID, City, Country, information related to remediation, the status of remediation, notes.

To create or update the properties of a custom attribute:

  1. In ePO - On-prem, go to Menu → Data Protection → DLP Incident Manager → Custom Attributes.

  2. Click Actions → New Item, to create a custom attribute. In the Custom Attributes page, enter the custom attribute name. Select the category of the custom attribute as Incident or User.

    You can also update an existing custom attribute. Click the Edit or Delete link to modify the existing custom attribute. Deleting a custom attribute deletes the assigned values from all incidents, instead, you can turn off the attribute for a particular incident.

  3. Click Save.

Use these attributes to assign custom attributes to all incidents. The priority of the custom attributes is shown in the top-down order. Click the up arrow and down arrow to change the priority. The custom attribute IDs aren't shown in the Custom Attributes table, but are available when you execute the customAttribute/list call.