When you remove a managed appliance from the Central Management System network, all aggregated data (including alert information) associated with the appliance is also removed. When you subsequently add back the appliance, the data is restored, but all alerts generated by the appliance are assigned new IDs.
Caution
Because the alerts have new IDs when an appliance is added back to the Central Management System appliance, Endpoint Security (HX) links for alerts will break if the alerts were generated by the appliance before it was removed from the Central Management System appliance.
Helix Enterprise > Helix Enterprise Integration Guide for Trellix Devices > Configuration > Preventing connections to a cloud Central Management System appliance
Central Management System (CMS) > Central Management System System Administration Guide Release 10.x > Appliances > Filtering alerts using tags and rules > Adding tags to alerts manually for managed appliances using the Web UI
Central Management System (CMS) > Central Management System System Administration Guide Release 10.x > Appliances > Monitoring aggregated alert data > Monitoring appliances using the Web UI