The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Search using Trellix Active Response

Prev Next

Use Active Response to search for current endpoint data.

  • Add a ePO - On-prem device with Active Response to Trellix ESM.

  • In ePO - On-prem, make sure that Send Restrictions and Receive Restrictions are set to All Systems or have a tag that is also tagged on the receiver (Server Settings → Topic Authorizations → Active Response Server API).

  1. Define search settings for the ePO - On-prem device.

    1. From the Trellix ESM dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png and select System properties.

    2. On the system navigation tree, select the device, then click Settings.png.

    3. Click Trellix ePO Properties, then click Connection.

    4. Select Enable DXL and specify an Agent Wake-up Port (default is 8081).

  2. On the Trellix ESM dashboard, select a view with a table widget, such as Event Analysis.

  3. Click an event, then click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png.

  4. Select Actions → Execute Active Response Search, then select a predefined search type.

    Note

    Search types are grayed out if the table doesn't have the appropriate fields for the search.

    • File details of the source and destination IP address, such as the operating system and name

    • User details

    • Source IP address process details for what established the connection

    • Destination IP address process details for what established the connection

    • Anyone connected to the same source or destination IP address