The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Attack Log

Prev Next

The Attack Log lists attacks with most recent being listed first. It contains alerts that are raised whenever there is a discrepancy in the traffic flowing through the network. The Sensors parsing the traffic detects any attack and raises an alert. Attack details are presented using multiple columns known as attributes. The attributes represent packet fields, such as source and destination IP address, as well as Sensor analysis fields such as attack severity. The Attack Log contains both acknowledged and unacknowledged alerts. You can acknowledge alerts and also update rules, quarantine hosts, tag endpoints, configure auto-acknowledgment rules, etc. You can also perform forensics on alerts for further analysis.

Note

Features that are not applicable to the Central Manager are explicitly mentioned in the relevant sections. All other features are applicable to both the Manager and the Central Manager.