Appliances can collect information to help determine how and why an alert was triggered. The information can help Trellix Technical Support determine how an alert was generated and whether it is a false positive. This saves time spent manually searching for and downloading alert data.
The information is gathered into a bundle. The bundle includes appliance and configuration information, submission and email analysis data, alert information, artifacts, samples, parsed logs, and so on.
Important
Use this feature only with guidance from Trellix Technical Support. Only Technical Support can retrieve the bundle stored on the appliance and open the password-protected bundle
.zipfile.
Log in to the Email Security - Server Web UI.
Click an alert to open the Alert Details page.
Click Prepare Triage Bundle.
When the bundle is ready, contact Trellix Technical Support to download and retrieve it.
Note
To collect the information using the API, you specify the alert UUID. See the Trellix API Reference Guide for details.