The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Import/Export watchlists

Prev Next

Share static watchlist values with multiple Trellix ESM devices in your organization by importing and exporting the watchlists.

  • Verify that you have administrator rights or belong to an access group with watchlist permissions.

    Without these privileges, you cannot edit, export, or remove private watchlists or watchlists that contain strings or rules names.

  • You must have a Trellix GTI license to export watchlists that contain GTI Malicious IPs and GTI Suspicious IPs values.

  1. From the Trellix ESM dashboard, click menu.png and select Watchlists.

  2. Click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png to list active and inactive watchlists.

  3. Export a watchlist.

    1. Select an existing watchlist and click Export.

      Note

      You cannot export Trellix GTI watchlists.

    2. Browse to the location where you want to export the watchlist file.

    3. Click Confirm.

  4. Import a watchlist.

    1. Select Import.

    2. Browse to the location of the watchlist file you want to import.

    3. Click Confirm.