The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Acknowledging all retrieved alerts

Prev Next

From the list of alerts grouped by attack rule name (the Alerts view of the Alerts tab), you can acknowledge all alerts in the entire list, or you can acknowledge alerts on a specific page of the list.

This procedure describes how to use the Alerts view in the Web UI Alerts tab to acknowledge all alerts in the entire list.

Requirements

  • You are logged in to the Web UI as Admin or Analyst.

Procedure

To acknowledge alerts on all pages of the Alerts view:

A filtered list of Alert Types that are not acknowledged displays.

  1. Select Alerts > Alerts.

  2. Under Filter, select Hide Acknowledged from the Alert pull-down and click the APPLY button.

  3. Select the check box located below the control bar and to the left of the Type column.

    Note

    Reconnaissance events and brute-force events (detected if IPS is licensed and activated on the Network Security) appear in the IPS tab. You cannot acknowledge these events.

  4. To acknowledge all alerts on all pages, click the SELECT ALL ALERTS button.

  5. Click Acknowledge. The Acknowledge Alert dialog appears.

  6. In the text box, enter a note about the acknowledgment action. Comment text is required.

  7. Click the Acknowledge button.

  8. To view all acknowledged alerts grouped by attack rule name, select Alerts > Alerts > Show Acknowledged.

  9. To view alert acknowledgment details, see Viewing alert acknowledgment history using the Web UI.