Appliances can collect information to help determine how and why an alert was triggered. The information can help File Protect Technical Support determine how an alert was generated and whether it is a false positive. This saves time spent manually searching for an downloading alert data.
The information is gathered into a bundle. The bundle includes appliance and configuration information, submission data, alert information, artifacts, samples, parsed logs, and so on.
Important
Use this feature only with guidance from File Protect Technical Support. Only Technical Support can retrieve the bundle stored on the appliance and open the password-protected bundle .zip file.
Log in to the Web UI.
Click an alert to open the Alerts page.
Click Prepare Triage Bundle.
When the bundle is ready, contact File Protect Technical Support to download and retrieve it.
Note
To collect the information using the API, you specify the alert UUID. See the Trellix API Reference Guide for details.