The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Clearing acknowledgments of all retrieved alerts

Prev Next

From the list of alerts grouped by attack rule name (the Alerts view of the Alerts tab), you can view a list of acknowledged alerts and clear those acknowledgments.

You can clear acknowledgments of all alerts in the entire list, or you can clear acknowledgments from a specific page of the list. This procedure describes how to use the Alerts view in the Web UI Alerts tab to clear acknowledgments of all retrieved alerts in the entire list.

Requirements

  • You are logged in to the Web UI as Admin or Analyst.

Procedure

To clear acknowledgment of all retrieved alerts:
  1. Click the Alerts tab.

  2. Click the Alerts link in the control bar.

  3. Select Filter > Alerts > Show Acknowledged.

  4. Select the top check box located below the control bar and to the left of the Type column.

    Every acknowledged alert in the current page only is selected.

    Note

    Reconnaissance events and brute-force events (detected if IPS is licensed and activated on the Network Security) appear in the IPS tab. You cannot acknowledge these events.

  5. To unacknowledge all alerts on all pages, click the SELECT ALL ALERTS button. If you go to any other page, all acknowledged alerts are selected.

    Click the Unacknowledge button. The Unacknowledge Alert dialog appears.

  6. In the text box, enter a note about the acknowledgment action. Comment text is required.

  7. Click Unacknowledge.

    The cleared acknowledgments are removed from the list, and the following message appears: