View and respond to active triggered alarms.
The Alarms Dashboard view shows a list of current alarms and gives information about each alarm. Alarm details appear in the Events pane when you select (click) an alarm from the list. You can change the date range of displayed alarms by clicking
the time frame.
Note
This view is can't be edited, but the alarm widget can be used in other views.
Click
and select Alarms.The Alarms Dashboard view opens and shows a list of unacknowledged triggered alarms. Click the column headings to sort the list.
Select the alarm from the list to view events associated with an alarm.
Event details appear in the Events pane.
Right-click an alarm and select an action from the context menu:
Option
Description
IP Address Details
Run a DNS lookup and retrieves the WHOIS record. If a Trellix GTI license is found, Threat Details are also returned.
Summarize By
View filtered on the alarm data you select.
Acknowledged or Unacknowledged
Change the status.
Note
The system removes acknowledged alarms from the Alarms pane but the alarms remain on the Triggered Alarms view.
Delete
Delete the alarm.
Copy to clipboard
Copy alarm information to your clipboard and paste it as text into another application.
Export to CSV
Export alarm data to a CSV file.
Edit Alarm
Edit an alarm.
Remote Commands
Add to an alarm - execute a remote command on any device that accepts SSH connections (except Trellix devices on the Trellix ESM).
Alarm Details
Get alarm details.
Right-click an event and select an action from the context menu:
Option
Description
Summarize By
View filtered on the alarm data you select.
Actions
Create watchlist, append watchlist, create alarm, remote commands and execution history
Incident Management
Create an incident based on the event or append the event to an incident.
Export to CSV
Export event data to a CSV file.
View Rule
View the event rule.
Filter On
On filters for event ID, source IP or port, destination IP or port and protocol.
Mark As Reviewed
Mark events as reviewed.
Delete Event
Delete events.
Browse Reference
Browse the reference.
Open Details Panel
Open event detail.
Aggregation settings
Add or modify the aggregation settings.
IP Address Details
Run a DNS lookup and retrieves the WHOIS record. If a Trellix GTI license is found, Threat Details are also returned.
Remedy Case
Send the event to remedy.
Look Around
Perform a look around.