The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Define inactivity threshold settings

Prev Next

When you set an inactivity threshold for a device, you are notified when no events or flows are generated in the specified time. If the threshold is reached, a yellow health status flag appears next to the device node on the system navigation tree. For child or client datasource, you can't set the inactivity threshold settings individually.

  1. From the Trellix ESM dashboard, click and select More Settings .

  2. On the system navigation tree, select the device and click GUID-F191D568-8B93-4D2C-9BFC-F1342FC407BD-low.png.

  3. On the device properties page, click Events, Flows and LogsInactivity Settings.

    The Inactivity Threshold window opens.

  4. Select the device, then click Edit.

  5. For each device, set the inactivity threshold to be notified when a device has not received events or flows for the time period you specify.