The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Troubleshooting alarm management issues

Prev Next

Use this information for basic alarm maintenance, troubleshooting, and reference.

ePO - On-prem not listed or no ePO - On-prem on the ePO - On-prem instance list

  • In the device tree verify, a ePO - On-prem device is connected to a Receiver.

  • On the ePO Properties page, check if the Enable DXL is selected.

    Note

    A Receiver can support only one ePO - On-prem device with DXL enabled. If you need multiple ePO - On-prem devices with DXL enabled, add a Receiver for each of them.

  • Verify if at least one DXL broker is available on the ePO - On-prem system.

  • Verify if the SIEM system has topic authorization permission to write to the DXL.

    • In ePO - On-prem, click Server SettingsDXL Topic Authorization.

    • Find DXL Fabric Infrastructure and verify if the Send Restrictions and Receive Restrictions columns have either All Systems or a tag which is also tagged on the Receiver within the ePO - On-prem.

Can't edit alarm

The alarms can't be edited from system dashboard Alarms menu.

Use Alarms Management to edit the alarms.