The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

EDRF API rate limits

Prev Next

Trellix APIs rate limit on the Trellix API gateway is categorized as free and paid allocations.

  • Enterprise subscription allocation: Includes 2,000 free API calls per day for Enterprise SKU customers (effective upon renewal or SKU update after April 2026).

  • Paid expansion allocation: Adds 2,000 API calls per day to your standard allocation for each API SKU you purchase.

Daily allocation overview

The following table outlines the daily API call rate limits:

Subscription

Included daily API Calls

Additional SKU required?

Enterprise subscription

2,000 free calls/day

No

Enterprise subscription + 1 API SKU

4,000 calls/day

Yes (1 quantity of paid API SKU)

Enterprise subscription + N API SKUs

2,000 + (N x 2,000) calls/day

Yes (N quantity of paid API SKUs)

Rate limits

API

Method

Rate limit (requests/seconds)

Investigations

POST

10/3600

GET

60/60

Investigations/id

PATCH

10/3600

GET

60/60

DELETE

10/3600

Investigations/metadata

POST

10/60

Investigations/evidence

GET

60/60

Searches/historical

POST

10/60

Searches/realtime

POST

6/60

Searches/queue-jobs

GET

120/60

Searches/historical/results

GET

60/60

Searches/realtime/results

GET

60/60

Remediation/host

POST

10/60

Remediation/search

POST

10/60

Remediation/actions

GET

60/60

Remediation/queue-jobs

GET

60/60

Remediation/threat

POST

10/60

Remediation/global-threat

POST

10/60

Remediation/exclusions

POST

10/60

GET

60/60

Remediation/exclusions/id

GET

60/60

PATCH

10/60

DELETE

10/60

Reactions

GET

60/60

POST

10/60

Reactions/id

GET

60/60

PATCH

10/60

DELETE

10/60

Threats

GET

60/60

Threats/id

GET

60/60

Threats/affectedhosts

GET

60/60

Threats/detections

GET

60/60

Alerts

GET

60/60

activity-feed

POST

200/60000

GET

200/6000

DELETE

200/60000

activity-feed/id

GET

200/6000

PATCH

200/60000

DELETE

200/60000