The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing the status of retroactive detection of a hash

Prev Next

Use the show submission id command to view the status of retroactive detection of a hash for a malware object on an Email Security - Server appliance. The submission status for a retroactive alert of a hash is marked as dti_detection in the output of the show submission id command. For details about the show submission id command, refer to the Trellix CLI Reference.

Note

You can view the status of retroactive detection of a hash only using the CLI.

Prerequisites

  • Administrator, Monitor, or Analyst access to the Email Security - Server appliance

  • An established connection to the Internet

  • Validate DTI access on the Email Security - Server appliance by using the show fenet status command. For details about how to validate DTI access, refer to the Email Security — Server System Administration Guide.

  • A CONTENT_UPDATES license for security content updates