The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Resolve alerts request parameters

Prev Next

Resolves alerts.

Service

resolve-alerts

Permission

Alert XML API

Version

4.4.9 or later

QUERY parameters are used to select which alerts will be resolved:

Parameter

Definition

HH$ExecutionTimeFrom

Date (format: dd MMM yyyy HH:mm:ss)

HH$ResolveReason

String

HH$Resolves

CSV Resolve IDs for the resolution field

HH$Id

Long

HH$Agents

CSV Agent IDs

HH$TagName

String

HH$DbGroupName

String

HH$ExecutionTimeTo

Date

HH$Databases

CSV Database IDs

HH$Operation

String

HH$OsUser

String

HH$ResolvedBy

User ID

HH$Severities

CSV ActionSeverity names (INFO, NOTICE, LOW, MEDIUM, and HIGH)

HH$SourceHost

String

HH$SourceIP

String

HH$Rules

CSV rule IDs

HH$ResolveNames

CSV Resolve name string

HH$RuleName

String

HH$QuarantineId

String

HH$ReleaseTimeAfter

Date

HH$ReleaseTimeBefore

Date

HH$ExecUser

String

HH$DatabaseId

Database Long

HH$ExecProgram

String

HH$Clientid

String

HH$Module

String

HH$ModifyDateFrom

Date

HH$ModifyDateTo

Date

HH$Sid

Integer

HH$TimeBackPeriod

Long

SET parameters are used to pass the values to be set for the alerts subset selected by the above parameters.

Parameter

Definition

HH$$resolveReason

String

HH$$resolveName

Resolve name string such as Resolved, Unresolved, and False Alarm.

For example, to resolve all the unresolved alerts received during the past five minutes, submit the request:

https://127.0.0.1:8443/xmlapi.svc?service=resolve-alerts&HH$ResolveNames=Unresolved&HH$TimeBackPeriod=300000&HH$$resolveName=Resolved