Malware-callback alerts indicate that the endpoint is sending confirmed callback traffic to a command-and-control server. The alerts only occur if an endpoint is infected with malware. If the Network Security appliance is in blocking mode, malware callbacks are blocked.
The endpoint should be investigated immediately and removed from the network during the process. Check local security logs and SIEM logs. You can also use the Endpoint Security (HX) server for triage investigation.
Central Management System (CMS) > Central Management System System Administration Guide Release 11.x > Appliances > Monitoring aggregated alert data > Monitoring appliances using the Web UI