The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Detailed alert information (Legacy)

Prev Next

The middle section of the alert details page contains information about the most recent event in this alert and about the triggering rule.

  • Most Recent Event—Details about the last event logged for this alert.

    • Click the down arrow next to a field value in this area to display a pivot menu. See Pivoting from event data.Pivoting from event data

    • A fraction appears for some fields. The value on the top (left) of the fraction indicates how many antivirus search engines found this field value to be malicious. The value on the bottom (right) of the fraction identifies the number of antivirus search engines that matched the field value. For example, (37/60) indicates that a field value was found to be potentially malicious by 37 out of 60 matching antivirus engines.

    • If an "i" appears for a field value, threat analysis information exists for the field. Click the "i" icon to see associated threat analysis information on the Intel tab. See Viewing intelligence details on alerts.Viewing intelligence details on alerts

    • Click URL Screenshot in the virus field to see a preview of the Web page pointed to by a URL in a phishing email.

  • Trellix Helix Rule

    • Name—A link to the rule that triggered this alert.

    • Rule Pack—The rule pack to which this rule belongs, if any.

    • Distinguishers—A field in an event that a rule uses to differentiate hits for the purpose of creating alerts. See About distinguishers for more information.

    • Threshold—The threshold set by the rule.

    • Interval—The interval set by the rule.

    • Query—A link to the TQL query that produced the event.

    • Queues—The alert queues, if any, to which the alert is assigned. [[NOTE: This may come back post-1.2]]