The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Description page (Automatic Response Builder)

Prev Next

Use the Description page of the Response Builder to specify a name, a description, event group and type, and status for an automatic response.

Option definitions

Option

Definition

Description

Allows you to type a description of this response.

Event

Specifies information about the event that triggers this automatic response. Event groups and their event types include:

  • Examples of server events include: Active directory synchronization failed (or succeeded); or Repository pull succeeded (or failed).

  • An example of a threat event is: Virus detected.

  • An example of a client event is: Product update succeeded (or failed).

Event groups are not necessarily a part of every product. Check the product documentation for information about events and automatic responses.

ePO Notification Events

Specifies the available ePO - On-prem notification event types, including:

  • Client — Events that occur on managed systems. For example, "Product update succeeded."

  • Server — Events that occur on the ePO - On-prem server. For example, "Repository pull failed."

  • Threat — Events that indicate a possible threat are detected. For example, "Virus detected."

Language

Allows you to select the language of response from the list.

Name

Allows you to type a name for the response. Spaces, underscores, and special characters are allowed.

Status

Allows you to select whether the response is enabled or disabled. The default is Enabled.