The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure alarms to use watchlists

Prev Next

Use watchlists as alarm conditions so that the alarm triggers when the system encounters an event that matches a value in the watchlist.

  • Verify that you have administrator rights or belong to an access group with alarm management permissions.

  • Verify that you have administrator rights or belong to an access group with watchlist permissions.

  1. From the Trellix ESM dashboard, click menu.png and select System Properties.

  2. Click Alarms, then add an alarm.

  3. On the Condition tab, find the Internal Event Match → Use Watchlist option and select if a watchlist contains the values for this alarm.

  4. On the Actions tab, identify what happens to the watchlist you set as an alarm condition. You can append (add) or remove values in that watchlist.

    Note

    This action requires that you identify a watchlist using the Internal Event Match condition type.