The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alert request parameters

Prev Next

Retrieves alerts information. The parameter are used to filter the alerts.

Service

alert

Permission

ALERT XML API

Version

4.4.9 or later

Parameter

Definition

HH$ExecutionTimeFrom

Date (format: dd MMM yyyy HH:mm:ss)

HH$ResolveReason

String

HH$Resolves

CSV Resolve IDs

HH$Id

Long

HH$Agents

CSV Agent IDs

HH$TagName

String

HH$DbGroupName

String

HH$ExecutionTimeTo

Date

HH$Databases

CSV Database IDs

HH$Operation

String

HH$OsUser

String

HH$ResolvedBy

User ID

HH$Severities

CSV ActionSeverity names (INFO, NOTICE, LOW, MEDIUM, and HIGH)

HH$SourceHost

String

HH$SourceIP

String

HH$Rules

CSV Rule IDs

HH$ResolveNames

CSV Resolve name string

HH$RuleName

String

HH$QuarantineId

String

HH$ReleaseTimeAfter

Date

HH$ReleaseTimeBefore

Date

HH$ExecUser

String

HH$DatabaseId

Database long

HH$ExecProgram

String

HH$Module

String

HH$ModifyDateFrom

Date

HH$ModifyDateTo

Date

HH$Sid

Integer

HH$TimeBackPeriod

Long

HH$pageSize

Long — The maximum number of results per call

The default value is 100 and the value -1 for all the results

Note

ResolveNames works only with already existing resolve types.

For example, to get maximum of 5000 unresolved alerts from host myhost, issue the following request:

https://127.0.0.1:8443/xmlapi.svc?service=alert&HH$SourceHost=myhost&HH$ResolveNames=Unresolved&HH$pageSize=5000