The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Identify endpoints where throttling is initiated

Prev Next

You can identify endpoints where Data Throttled and Data Dropped events are generated.

You can create an automatic response for these events.

  1. On the ePO - On-prem console, select Menu → Reporting → Solidcore Events.

  2. Review the event list and locate endpoints where these events are generated.

    Event

    Action

    Data Throttled

    Review the Object Name column for information about throttling of events for the corresponding endpoints. Based on the type of throttling, you must immediately review the throttling status and process data for the endpoint to make sure that you don't lose data.

    Data Dropped

    Review the Object Name column for information if data has started dropping for events. Typically, this occurs when data isn't processed quickly for the endpoint. Based on the type of throttling, you must immediately process data.