The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Assign a normalized ID to a data source

Prev Next

Events that result from fundamentally identical activities can be automatically grouped to make it easier to evaluate and hunt threats.

Similar events (Windows logons and Linux logons, for example) can be normalized as the same event type despite being generated from different rules.

Use the Normalized Dashboard view to see normalized events.

  1. On the device tree, select the data source.

  2. Click GUID-D5AACD7D-9544-4011-8E37-D57FED1D7387-low.png to open the Policy Editor.

  3. In the Filters/Tagging panel, click GUID-39D3D20D-6297-462D-A1A4-1A2646BCC50E-low.png next to Normalized ID.

  4. Select a Normalized ID and close the Policy Editor.

    Events from the selected data source appear on the Normalized Dashboard.