The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add search events to a case

Prev Next

You can add events from the search results table to a new or existing case. This adds context to your investigations.

To add search events to a new case:

  1. On the search results page, do one of the following:

    • To add a single event to a new case, at the end of the event row select More Options more-options.png > Add to New Case.

    • To add multiple events to a new case, select each event and then beside the search button select More Options more-options.png > Add to New Case.

  2. In the Create New Case window, enter the following:

    • A name for the case. The default is Case with Search <search string>.

    • A severity for the case.

    • A description. The default is the search string.

    • (Optional) A note to provide context for other analysts.

  3. Select Create & Back To Search or Create & Go To Case.

To add events to an existing case:

  1. On the search results page, do one of the following:

    • To add a single event to an existing case, at the end of the event row select More Options more-options.png > Add to Existing Case.

    • To add multiple events to an existing case, select each event and then beside the search button select More Options more-options.png > Add to Existing Case.

  2. In the Add to Existing Case window, select the checkbox beside the case you want to add the events to.

    Note

    You can only add events to one case at a time.

  3. (Optional) Enter a note to provide context for other analysts.

  4. Select Create & Back To Search or Create & Go To Case.