The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Acknowledge alerts

Prev Next

To keep track of incoming alerts, analysts need to acknowledge an alert so they and the rest of the SOC team know the alert has been reviewed, but that no other action was taken. Acknowledging alerts is commonly used to filter out alerts that are either a false positive or noise within your environment.

To acknowledge alerts:

  1. On the Alerts page, do one of the following:

    • For a single alert, at the end of the row click More Options more-options.png > Acknowledgment.

    • For multiple alerts, select the checkbox next to each alert name and click Actions > Acknowledgment.

      Note

      If you select fewer than 1,000 alerts, the update happens in real time. If you select more than 1,000 alerts, the update happens in the background and you cannot perform the action again until the process is finished.

  2. In the dialog, select a reason from the menu and enter an optional note.

  3. Click Save.