The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

High-level steps to make the integration work

Prev Next

Prerequisites:

You must make sure that you have:

  • Set up and configured a ePO - On-prem server.

  • Set up and configured the Threat Intelligence Exchange server and DXL brokers.

To implement the Threat Intelligence Exchange integration, you must follow a series of steps to make sure that the integration works as expected.

  1. Log on to the Manager.

  2. Configure ePO - On-prem by providing the appropriate ePO - On-prem server IP address and credentials.

  3. Configure DXL integration either for a domain or for a device.

  4. Create an advanced malware policy in which TIE / GTI File Reputation is enabled for one or more file types.

  5. Apply this policy to the Sensor ports you want to use and specify the direction of traffic that is to be monitored with this policy.

  6. Perform a configuration update on the Sensor.

The setup is ready to be used in a Threat Intelligence Exchange integration.