Trellix APIs rate limit on the Trellix API gateway is categorized as free and paid allocations.
Enterprise subscription allocation: Includes 2,000 free API calls per day for Enterprise SKU customers (effective upon renewal or SKU update after April 2026).
Paid expansion allocation: Adds 2,000 API calls per day to your standard allocation for each API SKU you purchase.
Daily allocation overview
The following table outlines the daily API call rate limits:
Subscription | Included daily API Calls | Additional SKU required? |
|---|---|---|
Enterprise subscription | 2,000 free calls/day | No |
Enterprise subscription + 1 API SKU | 4,000 calls/day | Yes (1 quantity of paid API SKU) |
Enterprise subscription + N API SKUs | 2,000 + (N x 2,000) calls/day | Yes (N quantity of paid API SKUs) |
Rate limits
API | Method | Rate limit (requests/seconds) |
|---|---|---|
Investigations | POST | 10/3600 |
GET | 60/60 | |
Investigations/id | PATCH | 10/3600 |
GET | 60/60 | |
DELETE | 10/3600 | |
Investigations/metadata | POST | 10/60 |
Investigations/evidence | GET | 60/60 |
Searches/historical | POST | 10/60 |
Searches/realtime | POST | 6/60 |
Searches/queue-jobs | GET | 120/60 |
Searches/historical/results | GET | 60/60 |
Searches/realtime/results | GET | 60/60 |
Remediation/host | POST | 10/60 |
Remediation/search | POST | 10/60 |
Remediation/actions | GET | 60/60 |
Remediation/queue-jobs | GET | 60/60 |
Remediation/threat | POST | 10/60 |
Remediation/global-threat | POST | 10/60 |
Remediation/exclusions | POST | 10/60 |
GET | 60/60 | |
Remediation/exclusions/id | GET | 60/60 |
PATCH | 10/60 | |
DELETE | 10/60 | |
Reactions | GET | 60/60 |
POST | 10/60 | |
Reactions/id | GET | 60/60 |
PATCH | 10/60 | |
DELETE | 10/60 | |
Threats | GET | 60/60 |
Threats/id | GET | 60/60 |
Threats/affectedhosts | GET | 60/60 |
Threats/detections | GET | 60/60 |
Alerts | GET | 60/60 |
activity-feed | POST | 200/60000 |
GET | 200/6000 | |
DELETE | 200/60000 | |
activity-feed/id | GET | 200/6000 |
PATCH | 200/60000 | |
DELETE | 200/60000 |