The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add alerts to a case

Prev Next

You can add alerts to a new or existing case.

To add alerts to a new case:

  1. On the Alerts page, do one of the following:

    • For a single alert, at the end of the alert row click More Options more-options.png > Add to New Case.

    • For multiple alerts, select the checkbox next to each alert and click Actions > Add to New Case.

      Note

      If you select fewer than 1,000 alerts, the update happens in real time. If you select more than 1,000 alerts, the update happens in the background and you cannot perform the action again until the process is finished.

  2. A case ID is assigned and the new case is added to the top of the cases table.

You can also open an alert from the alert table and add it to a new case. Select Case > Add to New Case. A case ID is assigned and the new case is added to the top of the cases table.

To add alerts to an existing case:

  1. On the Alerts page, do one of the following:

    • For a single alert, at the end of the alert row click More Options more-options.png > Add to Existing Case.

    • For multiple alerts, select the checkbox next to each alert and click Actions > Add to Existing Case.

      Note

      If you select fewer than 1,000 alerts, the update happens in real time. If you select more than 1,000 alerts, the update happens in the background and you cannot perform the action again until the process is finished.

  2. Enter the Case ID, choose a recent case, search for the name of case, or select View All Cases to open the Cases page.

You can also open an alert from the alert table and add it to an existing case. Select Case > Add to Existing Case and enter the Case ID, choose a recent case, search for the name of a case, or select View All Cases.