The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add endpoints to quarantine from Attack Log page

Prev Next

You can quarantine endpoints from the list of alerts displayed in the Attack Log page.

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.

  2. Select the alert whose IP has to be quarantined.

  3. Click Other Actions, and select Quarantine Endpoint. Click the endpoint IP address you want to quarantine.

    Add to Quarantine
    Add to Quarantine


    The Add to Quarantine pop-up opens.

  4. Update the following fields:

    Option

    Definition

    IP Address

    Enter the IP address of the endpoint.

    Device

    Select the specific device of the endpoint whose traffic originating from the IP address you want to block.

    Quarantine Duration

    Select the quarantine duration from the drop-down list.

    Remediate

    Select the checkbox to redirect the configured endpoint to the configured remediation portal.

    Note

    You can configure the remediation portal settings in Devices → Global → IPS Device Settings → Quarantine → Remediation Portal.

  5. Click Quarantine.