The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate Custom user defined reports

Prev Next

You can create a new report with a choice of data source, presentation and filter.

  1. Navigate to Analysis → Event Reporting → Custom Reports. Click New.

    You need to select the data sources for the report. Data source represent the database tables from where information is retrieved to generate the report. The following are the options for data source: Alert Data, Application Data, Endpoint Data, and Performance data.

  2. Click Next to set the display options for the report. Report can be displayed as a Table, Bar Chart, or Pie Chart.

  3. Click Next.

  4. Select the columns of choice that you want to include in the report output by selecting rows in the left panel.

  5. Click Next.

  6. Select a row in the left panel to view the Data Filter options.

    You can enhance the filter options for the fields selected in step 4 from the Available Fields options. Use the > and < options to add or remove conditions.

    Note

    The admin domain selected in the left pane has no impact on the reports generated. The admin domain data filter selected is explicitly to filter the reports that are generated.

    When you finish the selections, you can save your report query using Save As.

  7. In the Save Report page, you need to enter a Name and Description for the Query.

    You can also select the following options in the Save Query:

    • Automate Report Generation

    • Report Frequency

    • Select events to display

    • Report Format

  8. Click Finish to save the query.

  9. The report is saved and displayed in the Saved Reports section of the Custom Reports page.

  10. Select the report, and then click Run to view the Run Query.

  11. In the Run Query, enter the Data Options and the Report Format.

    Click Run, to run the report query. The generated report is displayed in the selected report format.

    When the Bar Chart display option is selected, the output contains both the bar chart and table. If you select the Pie Chart option, the Pie Chart and the table are displayed. If there are no alerts, only the table is displayed.

    Data Display Order:

    Table Type

    Bar Chart

    Pie Chart

    Table Only

    Alert information table

    Data is displayed in descending order

    Data is displayed in descending order

    Data is displayed in ascending order

    Once the Custom user defined Report is saved, you cannot change its data source.

    Note

    In the case of Host Event Table all table information (only table/table with bar chart/ table with pie chart) is displayed in an ascending order.