You can view and customize the threshold to fine-tune the number of attention-worthy threats.
Log on to Trellix EDR as an administrator.
Navigate to Menu → Configuration → Settings.
Under Finetune configuration, click Threat display options and select the threat display option you want. The options selected in the Threat display options page apply only to threat events displayed in the Monitoring dashboard.
The threat level views (such as Show less, Default, and Show more) are different from the severity filters (High, Medium, and Low) on the Monitoring page. The threat level views adjust what is included in your overall threat list based on potential threats, while the severity filters narrow the view of the currently displayed threats based on their assigned severity level. You can use both to fine-tune your monitoring view.
Show less threats — Displays only high-potential threat events. Use it to focus on the most urgent, confirmed threat events.
Default threat level (recommended) — Displays a balanced snapshot of your environment, showing all critical threats and other suspicious threat events that require further investigation.
Show more threats — Displays all identified threats, including low-potential threat events. Use this for in-depth investigations to explore a broader set of security data.
Show all threats — Displays all identified threat events, including informational and benign events. Use this for advanced investigations that include detailed troubleshooting, forensics, or auditing and compliance checks.
Important
Increasing the number of threats may result in false-positive visualization.