Remediating Trellix appliance alerts

Prev Next

You can take remediation actions on alerts sent from Network Security and Email Security — Server appliances from the Actions menu on the Events tab of the alert details page. The following example shows the actions for an Email Security — Server alert.

  • To download Network Security or Email Security — Server alert artifacts (if any), select Download Artifacts.

  • To release from quarantine emails associated with an Email Security — Server alert, select Release Email from Quarantine.

  • To delete from quarantine emails associated with an Email Security — Server alert, select Delete Email from Quarantine.

  • To download a text file containing the content of an email associated with an Email Security — Server alert, select Download Email.

  • To change the settings for an inline policy exception associated with a Network Security alert, select Manage Policy Exception.

Important

These actions are available only for alerts that are sent to Helix Enterprise directly from the appliance. If the appliance is managed by a Central Management appliance, use the no fenotify integ helix enable command on the Central Management appliance and the fenotify integ helix enable command on the managed appliance to allow the alerts to be sent directly.

See the User Guide for your appliance for details about these alert actions.