The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Documenting and tracking alert activity

Prev Next

Documenting and tracking the work carried out on an alert is crucial. It allows for information sharing and collaboration across the SOC team, and enables SOC leaders to export alert information to share with stakeholders. Alert management provides two ways to accomplish this: the Notes tab and the History tab.

The ability to add notes enables you to document and track your work. Alert notes use Markdown so you can create structured and easily readable notes. This includes the ability to apply bold text, create lists, and highlight important content. If an alert has to be reassigned or escalated, notes enable other team members to quickly understand what action you have taken on an alert.

Alert management automatically adds a record of each interaction with the alert on the History tab. This provides an audit log of all actions and activity taken by the analysts working on the alert. Alert history shows the date, time, user, and activity that was carried out. To ensure there is an accurate record of the work done, you cannot edit or delete this information.