The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Overview

Prev Next

As the foundation of the Trellix Security Information Event Management (SIEM) solution, Trellix Enterprise Security Manager gives you real-time visibility to all activity on your systems, networks, database, and applications.

Add Trellix devices to increase the power of Trellix ESM:

  • Trellix Enterprise Security Manager — The core device of the Trellix SIEM solution and the primary device on which an analyst identifies vulnerabilities and hunts threats. It is also where administrators configure the system, including data sources, alarms, rules, and so on. The ESM holds events and flows collected by receivers (ERCs).

  • Trellix Enterprise Security Manager - Event Receiver — Collects, parses, and normalizes large amounts of raw security data (required).

  • Trellix Data Streaming Bus — Facilitates device interconnection and provides a streaming data platform for external integrations (required for data sharing with 3rd-party applications).

  • Trellix Enterprise Security Manager - Enterprise Log Manager — Stores raw logs for compliance purposes (recommended).

  • Trellix Enterprise Security Manager - Enterprise Log Search— Searches raw logs quickly for forensic purposes (optional).

  • Trellix Enterprise Security Manager - Advanced Correlation Engine (Trellix ESM - ACE) — Correlates parsed data to identify trends and suspicious activity (recommended).

  • Trellix Enterprise Security Manager - Application Data Monitor — Monitors unencrypted Layer 7 session data to identify suspicious activity at the application and protocol level (optional).