The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Customize summary for triggered alarms and incidents

Prev Next

Allows you to select the data to include in the alarm summary and the incident summary of Field Match and Internal Event Match alarms.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select Trellix ESM and click Settings.png.

  3. Click Alarms, then click Add or Edit.

  4. On the Condition tab, select the Field Match or Internal Event Match for Type.

  5. On the Actions tab, select Create CaseConfigure.

  6. Select the fields to include in the incident summary and click OK.

  7. On the Actions tab, select Custom alarm summaryConfigure.

    The Triggered Alarm Summary Configuration opens.

  8. Click GUID-911771E2-BC63-4466-BDB0-4D486C98E7FA-low.png, then select the fields to include in the summary for the triggered alarm and click OK.

  9. Enter the information requested to create alarms and click Finish.