Trellix® Threat Intelligence Exchange (TIE) execution history displays systems that have executed the file associated with selected events.
A Trellix ePolicy Orchestrator - On-premises device with an attached Threat Intelligence Exchange server on Trellix ESM must exist.
On the system navigation tree, click the Trellix ePolicy Orchestrator - On-premises device.
On the Trellix ESM dashboard, select one or multiple Threat Intelligence Exchange events form the Events pane.
In the Events pane, click → → .
Note
On the TIE Execution History page, view the systems that have executed the Threat Intelligence Exchange file.
To add this data to your workflow, select a system and click
to:Create watchlists
Append to watchlist
Create an alarm
Add to block list
Export to CSV