The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Normalization

Prev Next

Combine similar events to reduce processing time and storage requirements.

Events that are fundamentally the same can be grouped to make it easier to evaluate and hunt threats. For example, you can normalize Windows logins and Linux logins so they appear in the system simply as logins. Normalization is configured as part of Advanced Syslog Parser rule configuration.

Normalization IDs

Use normalized IDs to:

  • Filter using a single ID

  • Filter by multiple folders or IDs at one time (using the Ctrl or Shift keys to select).

  • Filter first-level folders

    A mask (/5 for a first-level folder at the end of the ID) means Trellix ESM filters events by the selected subfolder IDs.

  • Filter second- or third-level folders

    A mask (/12 for a second-level folder, /18 for a third-level folder at the end of the ID) means Trellix ESM filters events by the selected subfolder IDs.

    Note

    The fourth level doesn't have a mask.

String normalization

Use string normalization to:

  • Associate string values with alias values

  • Import or export a .csv file of normalized string values

  • Filter queries by strings and its aliases

For example, the John Doe user name string, define a string normalization file where the primary string is John Doe with the following aliases:

  • DoeJohn

  • JDoe

  • john.doe@gmail.com

  • JohnD

You can then create a query with John Doe as a user nickname and filter by string normalization.

The resulting view displays all events associated with John Doe and his aliases, enabling you to check for logon inconsistencies where source IPs match but user names do not.