Collecting information to triage alerts

Prev Next

Managed Network Security, Email Security — Server, and Malware Analysis appliances can collect information to help determine how and why an alert was triggered. The information can help Trellix Technical Support determine how an alert was generated and whether it is a false positive. This saves time spent manually searching for and downloading alert data.

The information is gathered into a bundle. The bundle includes appliance and configuration information, submission and email analysis data, alert information, artifacts, samples, parsed logs, and so on, depending on the appliance type.

Important

Use this feature only with guidance from Trellix Technical Support. Only Technical Support can retrieve the bundle stored on the appliance and open the password-protected bundle .zip file.

To collect the information:
  1. Log into the Central Management System Web UI.

  2. Hover over Alerts and then select a Network Security or Email Security — Server alert page or a Malware Analysis analysis page.

  3. Click the alert or analysis ID to open its detail page.

  4. Click Prepare Triage Bundle.

  5. When the bundle is ready, contact Technical Support to download and retrieve it.

Note

To collect the information using the API, you specify the alert UUID. See the Trellix API Reference Guide for details.