The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Troubleshooting alarm management issues

Prev Next

Use this information for basic alarm maintenance, troubleshooting, and reference.

ePO - On-prem not listed or no ePO - On-prem on the ePO - On-prem instance list

  • In the device tree verify, a ePO - On-prem device is connected to a Receiver.

  • On the ePO Properties page, check if the Enable DXL is selected.

    Note

    A Receiver can support only one ePO - On-prem device with DXL enabled. If you need multiple ePO - On-prem devices with DXL enabled, add a Receiver for each of them.

  • Verify if at least one DXL broker is available on the ePO - On-prem system.

  • Verify if the SIEM system has topic authorization permission to write to the DXL.

    • In ePO - On-prem, click Server Settings → DXL Topic Authorization.

    • Find DXL Fabric Infrastructure and verify if the Send Restrictions and Receive Restrictions columns have either All Systems or a tag which is also tagged on the Receiver within the ePO - On-prem.

Can't edit alarm

The alarms can't be edited from system dashboard Alarms menu.

Use Alarms Management to edit the alarms.