The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Filter, sort, and refresh alerts

Prev Next

The volume of alerts generated in the Attack Log makes it difficult for the analysis of alerts. The different sorting and filtering options provided in the Attack Log helps drill-down only the necessary alerts for further analysis. Use the arrow keys at the bottom of the page to navigate back and forth between the alert pages.

Sort alerts

Alerts when generated are in unacknowledged state. Once an alert is acknowledged, a tick mark appears next to the alert in the acknowledged and unacknowledged column. You can sort the alerts by selecting any one of the three options, Unacknowledged, Acknowledged and Any Alert State. You can also sort the alerts based on the period in which the alerts were generated. The Custom Time Period option lets you customize the time period.

When the time period option is selected, the display shows the alert, attack counts, and other parameters for the chosen time period. The alert count displays the number of times each attack has been reported within the parameters. For example, for a query, there are two reported alerts (number of alerts = 2) and two reported attacks (attack count = 2) for the "ARP: ARP Spoofing Detected" attack. Thus, the "ARP: ARP Spoofing Detected" attack was detected and reported exactly twice during the queried period. Also, the number of alerts and attack count for the "Samba Trans2Open Buffer Overflow" attack: 74 alerts have been generated for this attack; however, there were 2133 attack instances. One or more attack instances was suppressed according to the configuration set.

When looking for a particular alert, you can enter the keyword for the alert in the Quick Search field and the results are automatically displayed in the log. Click Clear All Filters to undo all the filters applied.



The Clear All Filters button color changes to orange which indicates that a filter is active, and that the attack log is not displaying all the alerts. For example, if you want to filter the alerts detected by MVX engine, type mvx or MVX in the Quick Search field. The Clear All Filters button color changes to orange and the Manager filters MVX specific alerts.



Filter alerts

You can customize the columns in the Attack Log to view only the necessary details about the alert. You can rearrange/resize the columns to view the details according to your preference. Following are the column options for the alerts:

Column header Description
Acknowledged/unacknowledged alerts The tick mark indicates that the alert is acknowledged.
Attack Severity Indicates different colors based on the attack severity, high/medium/low/informational
Name Name of the attack
Event Displays various information about the attack
  • Time — Time at which the attack occurred
  • Direction — Transmission destination with regard to internal network (inbound or outbound)
  • Result — Result of the alerted attack

    The Result categories for alerted attacks are as follows:

    • Attack Successful — The attack was successful.
    • Inconclusive — The result of the attack is not known. This is most likely due to a generic policy, such as the Default or All-Inclusive policy where the policy rules are not environment specific. For example, this may be the result if an attack occurs against an irrelevant node.
    • Attack Failed — The attack had no impact.
    • n/a — The alert was raised for suspicious, but not necessarily malicious, traffic. This result is common for Reconnaissance attacks due to the nature of port scanning and endpoint sweeping.
    • Attack Blocked — Attacks blocked by a "Drop packets" Sensor response
    • Attack SmartBlocked — Attacks blocked by a "Drop packets" Sensor response as per GTI reputation response
    • DoS Blocking Activated — Applies to DoS traffic and indicates that the Sensor has identified traffic that is suspicious in nature that is exceeding its learned threshold or is not recognized based on its profile. The Sensor has started blocking unknown traffic, while attempting (on a packet-by-packet basis) to block only DoS traffic from a trusted source. The Sensor attempts to allow legitimate traffic to flow from the trusted source. Because of the nature of DoS attacks, one cannot be certain that 100% of bad traffic was blocked nor that 100% of 'good' traffic was permitted. For more in-depth description of Trellix IPS's DoS handling, see Denial-of-Service attacks.

    The following is the alert result status when Simulated Blocking is enabled.

    • Blocking Simulated (Attack Failed) — The attack had no impact.
    • Blocking Simulated (Attack Blocked) — An alert is raised for the attack that had potential impact.
    • Blocking Simulated (Attack Successful) — The attack was successful.
    • Blocking Simulated (Inconclusive) — The result of the attack is not known. This is most likely due to a generic policy, such as the Default or All-Inclusive policy where the policy rules are not environment specific. For example, this may be the result if an attack occurs against an irrelevant node.
    • Blocking Simulated (n/a) — The alert was raised for suspicious, but not necessarily malicious, traffic. This result is common for Reconnaissance attacks due to the nature of port scanning and endpoint sweeping.
    • Blocking Simulated (Attack SmartBlocked) — An alert is raised for the attack that had potential impact as per GTI reputation response.
  • Attack Count — Number of instances of the same attack
  • Relevance — Indicates if the endpoint is vulnerable to this particular attack
  • Alert ID — ID assigned to the alert
  • Assigned to — Displays the name of the user if the attack is assigned
Attack Displays specific information about the attack
  • Trellix IPS ID — ID of the Sensor from where the alert was generated
  • CVE ID — CVE ID of an attack that has been identified in the network and captured by the Sensor

    Note

    The CVE ID is displayed only for those attacks present in the signature set that have a valid CVE ID assigned to them.

    Note

    • In case you are performing a fresh installation of Trellix IPS Manager, the CVE ID column in the Attack Log page displays CVE IDs for all the alerts that have valid CVE IDs assigned to them in the signature set.
    • In case you are upgrading the Manager to version 10.1.7.44 from versions prior to 10.1.7.29, the CVE ID column in the Attack Log page displays CVE IDs for all the alerts that have valid CVE IDs assigned to them in the signature set.
    • In case you are upgrading the Manager to version 10.1.7.44 from version 10.1.7.29, 10.1.7.35, or 10.1.7.40, the CVE ID column in the Attack Log page displays CVE IDs only for the alerts (that have valid CVE IDs assigned to them in the signature set) generated post upgrade. You will not be able to view the CVE IDs for old alerts. In order to view CVE IDs for such alerts:
      1. Double-click on the old alert for which you want to view the details.

        The <Attack Name> panel opens on the right hand side.

      2. Click on the Description tab in the panel and scroll down to the Reference section.

        You can view the CVE ID in this section, provided the alert has a valid CVE ID assigned to it in the signature set.

  • BTP — Displays the BTP level as either High, Medium or Low
  • Attack Category — General attack type
  • Last Updated — Recent version of the signature set in which the attack was updated
Packet Capture You can export the packet capture for that alert.
Attacker Displays details about the attacker endpoint
  • IP Address — IP address of the attacker endpoint
  • Port — Port on which the attack was detected
  • Risk — Displays the risk level as High Risk, Medium Risk or Low Risk
  • Hostname — Name of the host from where the attack was generated
  • Country — Country of the attacker host
  • Proxy IP — IP address of the proxy server
Target Displays details about the target endpoint
  • IP Address — IP address of the target endpoint
  • Port — Port to which the attack is directed
  • Risk — Displays the risk level as High Risk, Medium Risk or Low Risk
  • Hostname — Name of the host to which the attack is directed
  • Country — Country of the target host
  • Proxy IP — IP address of the proxy server
Malware File Displays details about the attack in case of malware attacks
  • File Name — Name of the malware file
  • File Hash
    • MD5 — Displays the MD5 hash of the file
    • SHA1 — Displays the SHA1 hash of the file
    • SHA256 — Displays the SHA256 hash of the file
  • Malware Name — Name of the malware
  • Malware Confidence — Malware confidence level returned by the configured malware scanning engines
  • Engine — The configured scanning engine that detected the malware
Callback Activity Displays details about the callback activity for BOT attacks
  • Activity Name — Name of the callback activity for the BOT attacks
  • C&C Domain — Displays the C&C Domain of the callback activity
Endpoint Executable Displays details about the endpoints running the executables
  • Manager — Name of the Manager. This field is applicable for Central Manager only.
  • Name — Binary name of the executable
  • Hash — File hash of the executable
  • Malware Confidence — Displays the malware confidence level returned by the configured McAfee EIA. The malware confidence values are very high, high, medium, low, very low, and unknown.
Application Displays the Layer7 applications involved
Detection Displays details about the Sensor that detected the attack
  • Domain — Name of the domain to which the Sensor belongs
  • Device — Name of the device that detected the attack
  • Interface — Interface at which the attack was detected
Layer 7 Data Displays the following layer 7 data field details:
  • FTP Action
  • FTP Banner
  • FTP File Name
  • FTP Return Code
  • FTP User Name
  • HTTP CLSID
  • HTTP Host
  • HTTP Request Method
  • HTTP Response Content Type
  • HTTP Return Code
  • HTTP Server Type
  • HTTP URI
  • HTTP User-Agent
  • NetBIOS Action
  • NetBIOS File Name
  • SMTP Attachments
  • SMTP Banner
  • SMTP Recipients
  • SMTP Sender
  • TELNET User Name

You can view the protocols/fields that are enabled in the L7 Data Collection page under Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced.

You can also customize the settings for the protocols/fields in the L7 Data Collection page.

The default Percentage (%) value of flow memory re-allocated to collect layer 7 data is 20%.

Filtering alerts


In addition to the column filters, there are specific sub-filters for each column. These sub-filters are based on specific values for that column. For example, the Direction column will have Inbound, Outbound, Unknown, and Bi-directional as the sub-filters. The alerts are filtered based on the selected option. Further, the Sort Ascending and Sort Descending options for each column toggles the alerts either in ascending order or descending order.

Automatic refresh of alerts

Alerts in the Attack Log page can be refreshed automatically. Refer the following steps to enable or disable automatic refresh:

Note

Alerts can be refreshed manually by clicking

.

  1. Click .

    The Attcak Log Settings dialog box is displayed.

    Attack Log Settings


    Note

    Make sure that the set time period to fetch alerts is greater than the automatic refresh interval to not lose any alert data.

  2. From the Automatic Refresh drop-down, select the refresh interval based on your requirement.

    Note

    To disable automatic refresh select Disabled from the drop-down.

  3. Click Save.

Note

The Attack Log page refreshes automatically every time you visit the page from the Dashboard tab, Threat Explorer, Network Forensics, etc. when the Automatic Refresh is enabled.

Note

When you select an alert in the Attack Log page, with auto refresh enabled, the alert remains selected with the details panel still displaying the alert data though new alerts are added to the page.