The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

View Threat Intelligence Exchange execution history and set up actions

Prev Next

Trellix® Threat Intelligence Exchange (TIE) execution history displays systems that have executed the file associated with selected events.

A Trellix ePolicy Orchestrator - On-premises device with an attached Threat Intelligence Exchange server on Trellix ESM must exist.

  1. On the system navigation tree, click the Trellix ePolicy Orchestrator - On-premises device.

  2. On the Trellix ESM dashboard, select one or multiple Threat Intelligence Exchange events form the Events pane.

  3. In the Events pane, click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png → Actions → TIE Execution History.

    Note

    On the TIE Execution History page, view the systems that have executed the Threat Intelligence Exchange file.

  4. To add this data to your workflow, select a system and click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png to:

    • Create watchlists

    • Append to watchlist

    • Create an alarm

    • Add to block list

    • Export to CSV