The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alert suppression

Prev Next

Note

On a Network Security sensor or sensor-enabled Network Security integrated appliance, the events that trigger Malware Object and Web Infection alert types are classified as malicious by the MVX analysis engine that resides on the Intelligent Virtual Execution - Server compute nodes in a TrellixNetwork Security deployment.

Alert types such as Malware Object and Web Infection are analyzed using local MVX analysis engine rules, not the security content rules pushed through the Trellix DTI network. Events that trigger these alerts can be false positives, meaning the events are normal but are classified as malicious by the local MVX analysis engine.

You can stop a maximum of 15 MD5s and URLs combined that you consider to be false positives from being generated, pending investigation by theTrellix Security Content team. For example, if a file that needs to be distributed to all employees triggers an alert that you suspect is a false positive, you can suppress the alert so employees can receive the file while the alert is being investigated.

Suppression is end-to-end, so no notifications or reports are generated for suppressed alerts. The local signatures associated with suppressed MD5s and URLs are deleted. Subsequent traffic matching the suppressed MD5 or URL is not blocked.

The suppression of MD5s and URLs does not expire. They remain suppressed until you stop their suppression or resolve them.

Note

Network Security appliance users with the Admin or Analyst role can suppress alerts. Users with the Admin, Analyst, or Monitor role can view suppressed alerts.

When you suppress alerts, you actually suppress the MD5s and URLs that trigger them. You can suppress a maximum of 15 MD5s and URLs combined. For example, you can suppress seven MD5s and eight URLs or 15 URLs and no MD5s. Malware Objects can have both MD5s and URLs attached to them; Web Infections have only URLs attached to them. If you suppress both the MD5 and the URL attached to a Malware Object, it counts as two suppressed alerts.

All alerts that match a suppressed MD5 or URL are suppressed, and are no longer displayed on the Alerts page in the Web UI of the Network Security appliances and Central Management System appliance. The Total value at the top of this page is reduced by the number of alerts that matched the suppressed MD5 or URL, as well as the "Total Alerts" counts returned by the show alert summary CLI command.

Suppressing alerts using a Central Management System appliance

If your Network Security appliance is managed by a Central Management System appliance, you can suppress and manage alerts only from the Central Management System appliance Web UI. The suppression is pushed to all managed Network Security appliances, and the maximum number of 15 is the total for all managed appliances.

For example, suppose a Central Management System appliance manages a Network Security appliance that already has the maximum number of suppressed alerts. If you add another Network Security appliance with suppressed MD5s or URLs to the Central Management System appliance, a notice at the top of the Central Management System Suppressed Alerts page advises you to suppress or resolve alerts until the number is brought down to 15. After you suppress or resolve these extra alerts, the suppressed alerts on the Network Security appliances become out-of-sync, so a warning with a link to synchronize them is presented. For details, see the Central Management System Administration Guide.

Sharing the alert details package with Trellix

After you suppress alerts, the following data is packaged immediately:

  • Alert details, operating system (OS) changes, and any comments you added when you suppressed the alert.

  • Packet capture (PCAP) data, if you chose to include it.

  • The username of the person who suppressed the alert, which is used byTrellix Customer Support to track the ticket you open to initiate the investigation of the suspected false positive.

If you have an All CONTENT_UPDATES license, this package is immediately uploaded to the DTI network. If you have a one-way license, you can download the package to provideTrellix Customer Support.

Important

An All CONTENT_UPDATES license includes either the upload option or both the upload and download options. To verify whether this is enabled, run the show licenses CLI command, and make sure the CONTENT_UPDATES license has Sharing: all (ok).

Alert suppression workflow

The following steps describe the process you follow after you suppress MD5s and URLs attached to alerts.

  1. Suppress the alert as described in Suppressing alerts.

  2. Open a Customer Support ticket and do one of the following:

    • If your appliance has an All CONTENT_UPDATES license, include the Alert ID, LMS ID, and Suppression Time in the ticket. This information is displayed on the Suppressed Alerts page.

    • If your appliance has a one-way license, attach the alert details package you downloaded from the Suppressed Alerts page.

    The Security Content team determines whether the alert is a false positive and if it is, updates the security content.

  3. Receive confirmation from Customer Support that the false positive was addressed and find out which security content version you need to obtain.

  4. Apply this version of the security content update to your appliance.

  5. Resolve the suppressed MD5s and URLs.