The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add Auto-Acknowledgement Rule

Prev Next

To create auto-acknowledgement rules for alerts, complete the following tasks:

Note

Adding auto-acknowledgement rules for alerts is not applicable for the Central Manager.

Steps:

  1. Select Analysis → <Admin Domain Name> → Attack Log.

  2. Select the alert for which you want to create an auto-acknowledgement rule, and click Other Actions.

  3. Select Create Exception and click the Add Auto-Acknowledgement Rule option.

    The Add Auto-Acknowledgement Rule panel appears.

    Auto acknowledgement rule
    Auto acknowledgement rule


  4. The following fields are auto filled based on the alert selected. You can modify the details if required.

    Option

    Definition

    Attack Name

    Name of the attack for which the alert was generated.

    Attacker Endpoint

    IP address of the attacker.

    Target Endpoint

    IP address to which the attack was targeted.

    Expiration

    Date and time at which the rule expires.

    Modified

    Displays the last modified user name, date and time. The field is blank when creating the rule for the first time.

    Secondary Action

    The secondary/additional action to be performed on the alert other than auto acknowledging the alert.

    • None — No action taken other than auto acknowledging that particular alert.

    • Acknowledge all existing alerts that match — Acknowledges all the alerts that match the criteria. You can later view these alerts as acknowledged alerts in the Attack Log.

    Comment

    Type additional comments if required.

  5. Click Save to save the Ignore Rule.

    For more information on auto-acknowledgement, see the Auto-Acknowledgement section in the Trellix Intrusion Prevention System Product Guide.