For Malware Analysis, Central Management System, File Protect, and Network Security appliances, Trellix alert notification messages include the source and destination addresses of traffic observed on the appliance.
Except for IPS, the source address represents the victim, and the destination address represents the attacker. The same host address convention is used throughout the Web UI and CLI of the Trellix appliances.
For the Network Security and Central Management System appliances, you can change the notification source and destination values using the fenotify preferences normalize-ips-event enable command. For more information, see the CLI Reference.