The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How it works

Prev Next

Evolving security challenges require open, collaborative approaches to detect threats, reduce risk, and ensure compliance. Trellix Enterprise Security Manager (Trellix ESM) integrates with other Trellix products to resolve threats quickly without overloading resources.

What is the Trellix ESM workflow?

  1. Threat enters your organization.

  2. The Trellix Enterprise Security Manager - Event Receiver (SIEM Collector) collects data and events from security devices, databases, networks, systems, and applications.

  3. The SIEM Collector collects raw data.

  4. The SIEM Collector parses (or extracts) data into parts and relationships based on your specific syntax rules.

  5. The SIEM Collector normalizes (or aligns) collected values to one common scale and uses to identify known threats.

  6. The Trellix Enterprise Security Manager - Advanced Correlation Engine (Trellix ESM - ACE) correlates (or identifies) patterns in the information to identify potential security threats.

  7. Analyst monitors and identifies threats using dashboard, alarms, watchlists, incidents, and reports.

  8. Analyst identifies threat using Data Exchange Layer (DXL), Trellix Intelligent Sandbox, and Trellix® Threat Intelligence Exchange (TIE).

  9. Analyst uses Trellix ePolicy Orchestrator - On-premises to respond to threat immediately and automatically.

GUID-D171B85A-7E13-476C-AB35-2210C0EDA6E3-low.png