The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure alarms to use watchlists

Prev Next

Use watchlists as alarm conditions so that the alarm triggers when the system encounters an event that matches a value in the watchlist.

  • Verify that you have administrator rights or belong to an access group with alarm management permissions.

  • Verify that you have administrator rights or belong to an access group with watchlist permissions.

  1. From the Trellix ESM dashboard, click menu.png and select System Properties.

  2. Click Alarms, then add an alarm.

  3. On the Condition tab, find the Internal Event MatchUse Watchlist option and select if a watchlist contains the values for this alarm.

  4. On the Actions tab, identify what happens to the watchlist you set as an alarm condition. You can append (add) or remove values in that watchlist.

    Note

    This action requires that you identify a watchlist using the Internal Event Match condition type.