The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add exceptions to event aggregation settings

Prev Next

Aggregation settings apply to all events generated by a device. You can create exceptions for individual rules if the general settings don't apply to the events generated by that rule.

  1. On the views pane, select an event generated by the rule you want to add an exception for.

  2. Click the Menu icon GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png, then select Modify Aggregation Settings.

  3. Select the field types you want to aggregate from the Field 2 and Field 3 drop-down lists.

    Important

    The fields you select in Field 2 and Field 3 must be different types or an error results. When you select these field types, the description for each aggregation level changes to reflect the selections you made. The time limits for each level depend on the event aggregation setting you defined for the device.

  4. Click OK to save your settings, then click Yes to continue.

  5. Deselect devices if you do not want to roll out the changes to them.

  6. Click OK to roll out the changes to the devices that are selected.

The Status column shows the status of the update as the changes are rolled out.