The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Customize summary for triggered alarms and incidents

Prev Next

Allows you to select the data to include in the alarm summary and the incident summary of Field Match and Internal Event Match alarms.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select Trellix ESM and click Settings.png.

  3. Click Alarms, then click Add or Edit.

  4. On the Condition tab, select the Field Match or Internal Event Match for Type.

  5. On the Actions tab, select Create Case → Configure.

  6. Select the fields to include in the incident summary and click OK.

  7. On the Actions tab, select Custom alarm summary → Configure.

    The Triggered Alarm Summary Configuration opens.

  8. ClickGUID-911771E2-BC63-4466-BDB0-4D486C98E7FA-low.png, then select the fields to include in the summary for the triggered alarm and click OK.

  9. Enter the information requested to create alarms and click Finish.