Handling Trellix Endpoint Security (HX) Notification Alerts

Prev Next

After you enable malware detection, quarantine, and file cleaning on your host endpoints, you can enable Trellix Endpoint Security (HX) notification alerts. This allows local users to receive a notification alert on the host endpoint when a specific malware protection activity occurs.

Some notification alerts are configurable in the Web UI or the API. See Managing Malware Protection Notification Alerts for more information. See the Endpoint Security (HX) REST API Guide for information on using the API to enable and disable the malware protection notification alerts.

Important

Trellix Endpoint Security (HX) xAgent version 26 and later supports Trellix Endpoint Security (HX) notification alerts on the Windows endpoints only. They are not supported for host endpoints running Windows XP, Vista, or Server 2003.

If malware protection is disabled, including malware detection (Signature and Heuristic Detections) and quarantine, notification alerts will not appear on the host endpoint.

This section covers the types of Trellix Endpoint Security (HX) notification alerts and how to handle notification alerts on the endpoint.

Trellix Endpoint Security (HX) Notification Alert Types

Trellix Endpoint Security (HX) notification alerts that appear on the host endpoint when malware is detected or when infected files are quarantined or cleaned do not require user interaction. These notification alerts are informational only and provide the local user with the malware name or the name of the infected file.

MalwareProtect_FileQuarantine.png

The appearance of Trellix Endpoint Security (HX) notification alerts depends on the version of Windows running on your endpoints. For example, host endpoints running Windows 10 display Trellix Endpoint Security (HX) notification alerts in a small window on the desktop. You can also view them in the Windows Action Center.

The table below lists the types of notification alerts that may appear on the host endpoint and the supported configuration methods for each.

Notification Alert Types

Description

Purpose

Configurable

Web UI

API

Malware Infection Detected

This notification alert appears on the host endpoint when malware detection identifies an infected file or application.

Informational only

No

No

File Quarantined

This notification alert appears on the host endpoint when malware protection places an infected file or application in quarantine.

Informational only

Yes

Yes

File Clean

This notification alert appears on the host endpoint when malware protection cleans an infected file.

Informational only

Yes

Yes

Update FireEye Endpoint Security

This notification alert appears on the host endpoint when the malware definitions are out of date and prompts the user to update the malware definitions.

Requires user interaction

No

No

Updating Malware Definitions through Notifications Alerts

Malware Protection uses malware definitions to detect and identify files infected by malware. When malware definitions are out of date on your host endpoint, the Trellix Endpoint Security (HX) xAgent malware protection engine sends a notification alert to prompt the user to update the malware definitions. Malware definitions should be updated every 7 days.

To update malware definitions on the host endpoint from a FireEye Endpoint Security notification alert:

Notifcation Alert FES Update.png
  1. Log in to your host endpoint running Trellix Endpoint Security (HX) xAgent version 28.

  2. Click on the Update FireEye Endpoint Security notification alert in the task bar.

  3. Follow the prompts on your endpoint to update the malware definitions.

To update malware definitions on the host endpoint from the Windows Control Panel:

FSE Update in Windows Action Center.png
  1. Log in to your host endpoint running Trellix Endpoint Security (HX) xAgent version 28.

  2. Go to the Windows Control Panel > Action Center.

  3. Click the Update Now button for Trellix Endpoint Security (HX) to update the malware definitions.