The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Check device status

Prev Next

Device status alerts (active flags) indicate issues reported by health monitors.

Each Trellix SIEM device includes a health monitor. When a device is not healthy, a red flag, a yellow flag, or a red x appears on the device tree next to the device.

  • Red flag - device is not functioning properly

  • Yellow flag - the device is functioning, but has issues

  • Red x (data sources only) - the data source is disabled

You can click a flag to see more detailed information.

  1. To see a list of issues for a Data Streaming Bus, right-click the device on the Data Streaming Bus Configuration page (System PropertiesData Streaming Bus) and select View Health Monitor Data.

  2. To see a list of issues for other devices, click the red or yellow flag next to the device on the device tree.

    A flag on this type of node...

    Opens...

    System or group

    The Device Status Alerts Summary page, which is a summary of the status alerts for the devices associated with the system or group. It can display these status alerts:

    • Drive Space — A hard drive is full or running low on space. Could include the hard drive on the Trellix ESM, redundant Trellix ESM, or remote mount point.

    • Critical — The device is not working properly.

    • Warning — Something on the device is not functioning properly.

    • Informational — The device is working properly but the device status level changed.

    • Out of Sync — The virtual device, data source, or database server settings on the Trellix ESM are out of sync with what is actually on the device.

    • Rolled over — The log table for this device ran out of space so it has rolled over. This means that the new logs are writing over the old logs.

    • Inactive — The device has not generated events or flows in the inactivity threshold time period.

    • UnknownTrellix ESM could not connect to the device.

    Drive space, Rolled over, and Informational flags can be resolved by checking the boxes next to the flags and clicking Clear Selected or Clear All.

    Device

    The Device Status Alerts page, which has buttons that take you to locations for resolving the problem. It might include these buttons:

    • Log — The System Log (for Local Trellix ESM) or Device Log page shows a summary of all actions that have taken place on the system or device.

    • Virtual Devices, Data Sources, VA Sources, or Database Servers — Lists the devices of this type on the system, allowing you to check for problems.

    • Inactive — The Inactivity Threshold page shows the threshold setting for all devices. This flag indicates that the device has not generated an event in the interval specified.