The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Historical correlation

Prev Next

Use historical correlation to correlate past events.

When the system discovers a new vulnerability, check your historical events and logs to determine whether your organization was exploited in the past. Replay historical events using the Risk Correlation rule-less correlation engine and the standard rule-based event correlation engine.

Examine historical events against today's threat landscape in these situations:

  • Correlation was not set up during the time certain events triggered; correlating those events can reveal valuable information.

  • Set up new correlation based on past triggered events and test the new correlation to confirm results.

Be aware of the following when using historical correlation:

  • Real-time correlation cannot run until you disable historical correlation.

  • Event aggregation skews risk distribution.

  • When you move the Risk Manager back to real-time risk correlation, tune the thresholds.

To set up and run historical correlation, you must:

  1. Add a historical correlation filter.

  2. Run a historical correlation.

  3. Download and view the correlated historical events.