The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Investigate incidents

Prev Next

Create and track cases to help ensure effective responses.

Incident Management appears on the dashboard as two widgets - Cases and Source Events. You can add widgets to the view to make it more useful.

  1. On the dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png and select Incident Management.

    A summary of cases and a list of source events appear.

  2. Review and edit the case information.

    • Case ID - a system-generated unique identifier (you cannot change this ID)

    • Case Summary (up to 255 characters)

    • Assignee - the user responsible for the case

    • Case Severity - a number between 1 and 100 indicating the potential harm of the case. A higher number indicates a greater threat.

    • (Optional) Organization to which the case is assigned

    • Status:Open (default), Closed, or a custom status you create (Incident ManagementCase Statusadd case status)

    • Notes that indicate actions taken. The system automatically records:

      • Old and new values for changes

        ---- Severity Changed on 04-22-2009 at 09:39
        old: Low
        new: High
      • Case is opened, closed, or reassigned

      • Changes to summary, severity, organization, or events

      • History of users who accessed the case