The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

View and manage triggered alarms

Prev Next

View and respond to active triggered alarms.

The Alarms Dashboard view shows a list of current alarms and gives information about each alarm. Alarm details appear in the Events pane when you select (click) an alarm from the list. You can change the date range of displayed alarms by clicking GUID-F2346495-5442-45C7-8AF9-5AB22268487D-low.png the time frame.

Note

This view is can't be edited, but the alarm widget can be used in other views.

  1. Click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png and select Alarms.

    The Alarms Dashboard view opens and shows a list of unacknowledged triggered alarms. Click the column headings to sort the list.

  2. Select the alarm from the list to view events associated with an alarm.

    Event details appear in the Events pane.

  3. Right-click an alarm and select an action from the context menu:

    Option

    Description

    IP Address Details

    Run a DNS lookup and retrieves the WHOIS record. If a Trellix GTI license is found, Threat Details are also returned.

    Summarize By

    View filtered on the alarm data you select.

    Acknowledged or Unacknowledged

    Change the status.

    Note

    The system removes acknowledged alarms from the Alarms pane but the alarms remain on the Triggered Alarms view.

    Delete

    Delete the alarm.

    Copy to clipboard

    Copy alarm information to your clipboard and paste it as text into another application.

    Export to CSV

    Export alarm data to a CSV file.

    Edit Alarm

    Edit an alarm.

    Remote Commands

    Add to an alarm - execute a remote command on any device that accepts SSH connections (except Trellix devices on the Trellix ESM).

    Alarm Details

    Get alarm details.

  4. Right-click an event and select an action from the context menu:

    Option

    Description

    Summarize By

    View filtered on the alarm data you select.

    Actions

    Create watchlist, append watchlist, create alarm, remote commands and execution history

    Incident Management

    Create an incident based on the event or append the event to an incident.

    Export to CSV

    Export event data to a CSV file.

    View Rule

    View the event rule.

    Filter On

    On filters for event ID, source IP or port, destination IP or port and protocol.

    Mark As Reviewed

    Mark events as reviewed.

    Delete Event

    Delete events.

    Browse Reference

    Browse the reference.

    Open Details Panel

    Open event detail.

    Aggregation settings

    Add or modify the aggregation settings.

    IP Address Details

    Run a DNS lookup and retrieves the WHOIS record. If a Trellix GTI license is found, Threat Details are also returned.

    Remedy Case

    Send the event to remedy.

    Look Around

    Perform a look around.