The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Correlation

Prev Next

Identify and score threat events in real time, using both rule- and risk-based logic.

Some activities on your network appear benign when viewed in isolation, but become suspicious when viewed in a larger context of multiple related activities. Use correlation to look across multiple events and flows to detect patterns that indicate a larger threat.

You can set up Configure Trellix ESM - ACE using real-time or historical modes:

Correlation can be performed in real time for immediate risk analysis and in historical mode to reexamine older activities to find occurrence of risks not understood then (such as zero-day attacks).

  • Real-time mode — analyzes events as they are collected for immediate threat and risk detection.

  • Historical mode — replays available data collected through either or both correlation engines for historical threat and risk detection. When Trellix ESM - ACE discovers new zero-day attacks, it determines whether your organization was exposed to that attack in the past.

Trellix ESM - ACE devices supplement the existing event correlation capabilities for Trellix ESM by providing two dedicated correlation engines. Configure each Trellix ESM - ACE device with its own policy, connection, event and log retrieval settings, and risk managers.

  • Risk correlation — generates a risk score using rule-less correlation. Rule-based correlation only detects known threat patterns, requiring constant signature tuning and updates to be effective. Rule-less correlation replaces detection signatures with a one-time configuration: Identify what is important to your business (such as a particular service or application, a group of users, or specific types of data). Risk correlation then tracks all activity related to those items, building a dynamic risk score that raises or lowers based on real-time activity.

    When a risk score exceeds a certain threshold, Trellix ESM - ACE generates an event and alerts you to growing threat conditions. Or, the traditional rule-based correlation engine can use the event as a condition of a larger incident. Trellix ESM - ACE maintains a complete audit trail of risk scores for full analysis and investigation of threat conditions over time.

  • Rule-based correlation — detects threats using traditional rule-based event correlation to analyze collected information in real time. Trellix ESM - ACE correlates all logs, events, and network flows with contextual information, such as identity, roles, vulnerabilities, and more—to detect patterns indicative of a larger threat.

    Trellix Enterprise Security Manager - Event Receivers support network-wide, rule-based correlation. Trellix ESM - ACE complements this capability with a dedicated processing resource that correlates larger volumes of data, either supplementing existing correlation reports or off-loading them completely.