The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add alerts and artifacts to an existing case

Prev Next

You can add one or more alerts to an existing case from the Alerts page. After 90 days a read-only version of the alert and its associated events remains available until 13 months after the alert was generated. This allows you to see the full context of a case after 90 days, as well as retaining this information for audit purposes.

To add an alert from an existing case:

  1. Open the case, select the Related Alerts tab, and then click Add Alerts.

  2. Select all the alerts you want to add to the case, and then click Add Alerts.

To add alerts to an existing case from the alerts page:

  1. On the Alerts page, do one of the following:

    • For a single alert, at the end of the alert row click More Options more-options.png > Add to Existing Case.

    • For multiple alerts, select the checkbox next to each alert and click Actions > Add to Existing Case.

  2. Enter the Case ID, choose a recent case, or select View All Cases to open the Cases page.

You can add an artifact to an existing case from the Case Timeline tab on the case details page.

To add an artifact to an existing case:

  1. Open the case and select the Case Timeline tab.

  2. Click Actions > Add artifact.

  3. In the dialog, select a type of artifact from the menu, enter a name, and an optional note.

  4. Click Create.