The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Filter, sort, and refresh alerts

Prev Next

The volume of alerts generated in the Attack Log makes it difficult for the analysis of alerts. The different sorting and filtering options provided in the Attack Log helps drill-down only the necessary alerts for further analysis. Use the arrow keys at the bottom of the page to navigate back and forth between the alert pages.

Sort alerts

Alerts when generated are in unacknowledged state. Once an alert is acknowledged, a tick mark appears next to the alert in the acknowledged and unacknowledged column. You can sort the alerts by selecting any one of the three options, Unacknowledged, Acknowledged and Any Alert State. You can also sort the alerts based on the period in which the alerts were generated. The Custom Time Period option lets you customize the time period.

When the time period option is selected, the display shows the alert, attack counts, and other parameters for the chosen time period. The alert count displays the number of times each attack has been reported within the parameters. For example, for a query, there are two reported alerts (number of alerts = 2) and two reported attacks (attack count = 2) for the "ARP: ARP Spoofing Detected" attack. Thus, the "ARP: ARP Spoofing Detected" attack was detected and reported exactly twice during the queried period. Also, the number of alerts and attack count for the "Samba Trans2Open Buffer Overflow" attack: 74 alerts have been generated for this attack; however, there were 2133 attack instances. One or more attack instances was suppressed according to the configuration set.

When looking for a particular alert, you can enter the keyword for the alert in the Quick Search field and the results are automatically displayed in the log. Click Clear All Filters to undo all the filters applied.

GUID-82FFF24D-9F6C-450F-9554-4292A9EBBE6D-low.png

The Clear All Filters button color changes to orange which indicates that a filter is active, and that the attack log is not displaying all the alerts. For example, if you want to filter the alerts detected by IVX engine, type ivx or IVX in the Quick Search field. The Clear All Filters button color changes to orange and the Manager filters IVX specific alerts.

GUID-E7B45092-449D-4FB5-8250-933021FA3F9D-low.png

Filter alerts

You can customize the columns in the Attack Log to view only the necessary details about the alert. You can rearrange/resize the columns to view the details according to your preference. Following are the column options for the alerts:

Column header

Description

Acknowledged/unacknowledged alerts

The tick mark indicates that the alert is acknowledged.

Attack Severity

Indicates different colors based on the attack severity, high/medium/low/informational

Name

Name of the attack

Event

Displays various information about the attack

  • Time — Time at which the attack occurred

  • Direction — Transmission destination with regard to internal network (inbound or outbound)

  • Result — Result of the alerted attack

    The Result categories for alerted attacks are as follows:

    • Attack Successful — The attack was successful.

    • Inconclusive — The result of the attack is not known. This is most likely due to a generic policy, such as the Default or All-Inclusive policy where the policy rules are not environment specific. For example, this may be the result if an attack occurs against an irrelevant node.

    • Attack Failed — The attack had no impact.

    • n/a — The alert was raised for suspicious, but not necessarily malicious, traffic. This result is common for Reconnaissance attacks due to the nature of port scanning and endpoint sweeping.

    • Attack Blocked — Attacks blocked by a "Drop packets" Sensor response

    • Attack SmartBlocked — Attacks blocked by a "Drop packets" Sensor response as per GTI reputation response

    • DoS Blocking Activated — Applies to DoS traffic and indicates that the Sensor has identified traffic that is suspicious in nature that is exceeding its learned threshold or is not recognized based on its profile. The Sensor has started blocking unknown traffic, while attempting (on a packet-by-packet basis) to block only DoS traffic from a trusted source. The Sensor attempts to allow legitimate traffic to flow from the trusted source. Because of the nature of DoS attacks, one cannot be certain that 100% of bad traffic was blocked nor that 100% of 'good' traffic was permitted. For more in-depth description of Trellix IPS's DoS handling, see Denial-of-Service attacks.

    The following is the alert result status when Simulated Blocking is enabled.

    • Blocking Simulated (Attack Failed) — The attack had no impact.

    • Blocking Simulated (Attack Blocked) — An alert is raised for the attack that had potential impact.

    • Blocking Simulated (Attack Successful) — The attack was successful.

    • Blocking Simulated (Inconclusive) — The result of the attack is not known. This is most likely due to a generic policy, such as the Default or All-Inclusive policy where the policy rules are not environment specific. For example, this may be the result if an attack occurs against an irrelevant node.

    • Blocking Simulated (n/a) — The alert was raised for suspicious, but not necessarily malicious, traffic. This result is common for Reconnaissance attacks due to the nature of port scanning and endpoint sweeping.

    • Blocking Simulated (Attack SmartBlocked) — An alert is raised for the attack that had potential impact as per GTI reputation response.

  • Attack Count — Number of instances of the same attack

  • Relevance — Indicates if the endpoint is vulnerable to this particular attack

  • Matched Threat Feed — The name of the threat feed which includes the matching IoC detected in the alert.

  • Alert ID — ID assigned to the alert

  • Assigned to — Displays the name of the user if the attack is assigned

Attack

Displays specific information about the attack

  • Trellix IPS ID — ID of the Sensor from where the alert was generated

  • CVE ID — CVE ID of an attack that has been identified in the network and captured by the Sensor

    Note

    The CVE ID is displayed only for those attacks present in the signature set that have a valid CVE ID assigned to them.

    Note

    • In case you are performing a fresh installation of Trellix IPS Manager, the CVE ID column in the Attack Log page displays CVE IDs for all the alerts that have valid CVE IDs assigned to them in the signature set.

    • In case you are upgrading the Manager to version 10.1.7.44 from versions prior to 10.1.7.29, the CVE ID column in the Attack Log page displays CVE IDs for all the alerts that have valid CVE IDs assigned to them in the signature set.

    • In case you are upgrading the Manager to version 10.1.7.44 from version 10.1.7.29, 10.1.7.35, or 10.1.7.40, the CVE ID column in the Attack Log page displays CVE IDs only for the alerts (that have valid CVE IDs assigned to them in the signature set) generated post upgrade. You will not be able to view the CVE IDs for old alerts. In order to view CVE IDs for such alerts:

      1. Double-click on the old alert for which you want to view the details.

        The <Attack Name> panel opens on the right hand side.

      2. Click on the Description tab in the panel and scroll down to the Reference section.

        You can view the CVE ID in this section, provided the alert has a valid CVE ID assigned to it in the signature set.

  • BTP — Displays the BTP level as either High, Medium or Low

  • Attack Category — General attack type

  • Last Updated — Recent version of the signature set in which the attack was updated

Packet Capture

You can export the packet capture for that alert.

Mitre Attack Details

Displays key components of the Mitre matrix table for an attack or alert:

  • Tactic — Name of the adversarial tactic matching with the attack or alert

  • Technique — Name of the corresponding adversarial technique matching with the attack or alert

  • Sub-Technique — Name of the corresponding adversarial sub-technique matching with the attack or alert

  • Technique/Sub-Technique ID — ID of the specific technique/sub-technique in the <techniqueID.sub-techniqueID> format. For example, in the ID T1595.001, T1595 represents the technique Active Scanning and 001 represents the corresponding sub-technique named Scanning IP Blocks.

Note

Mitre Attack Details column option is available in both Trellix IPS Manager and Central Manager.

Note

If an attack matches with multiple tactics, techniques, and/or sub-techniques, their names along with applicable technique/sub-technique IDs are shown in the respective fields under the Mitre Attack Details column.

When an attack is mapped to multiple tactics, techniques, and/or sub-techniques, there is one-to-one correspondence among the tactics, techniques, sub-techniques, and technique/sub-technique IDs. For example, the first tactic corresponds to the first technique, sub-technique, technique/sub-technique ID, and so on.

Note

If the Tactic, Technique, Sub-Technique, or Technique/Sub-Technique ID is not available for any alert or attack, that particular field is displayed as ---.

Note

Mitre attack related details in the Attack Log are not shown for older alerts.

Attacker

Displays details about the attacker endpoint

  • IP Address — IP address of the attacker endpoint

  • Port — Port on which the attack was detected

  • Risk — Displays the risk level as High Risk, Medium Risk or Low Risk

  • Hostname — Name of the host from where the attack was generated

  • Country — Country of the attacker host

  • Proxy IP — IP address of the proxy server

Target

Displays details about the target endpoint

  • IP Address — IP address of the target endpoint

  • Port — Port to which the attack is directed

  • Risk — Displays the risk level as High Risk, Medium Risk or Low Risk

  • Hostname — Name of the host to which the attack is directed

  • Country — Country of the target host

  • Proxy IP — IP address of the proxy server

Malware File

Displays details about the attack in case of malware attacks

  • File Name — Name of the malware file

  • File Hash

    • MD5 — Displays the MD5 hash of the file

    • SHA1 — Displays the SHA1 hash of the file

    • SHA256 — Displays the SHA256 hash of the file

  • Malware Name — Name of the malware

  • Malware Confidence — Malware confidence level returned by the configured malware scanning engines

  • Engine — The configured scanning engine that detected the malware

Callback Activity

Displays details about the callback activity for BOT attacks

  • Activity Name — Name of the callback activity for the BOT attacks

  • C&C Domain — Displays the C&C Domain of the callback activity

Endpoint Executable

Displays details about the endpoints running the executables

  • Manager — Name of the Manager. This field is applicable for Central Manager only.

  • Name — Binary name of the executable

  • Hash — File hash of the executable

  • Malware Confidence — Displays the malware confidence level returned by the configured McAfee EIA. The malware confidence values are very high, high, medium, low, very low, and unknown.

Application

Displays the Layer7 applications involved

Detection

Displays details about the Sensor that detected the attack

  • Domain — Name of the domain to which the Sensor belongs

  • Device — Name of the device that detected the attack

  • Interface — Interface at which the attack was detected

Layer 7 Data

Displays the following layer 7 data field details:

  • NetBIOS Action

  • NetBIOS File Name

  • Relevant fields of command SMB CMD NEGOTIATE in the request direction only

  • Relevant fields of the command SMB CMD TREE-CONNECT-ANDX in the request direction only

  • Relevant fields of the command SMB CMD Trans in the request direction only

  • Relevant fields of the command SMB CMD Trans2 in the request direction only

  • Relevant fields of the command SMB Header in both request and response directions

  • Relevant fields of the command SMBv2 Create in both request and response directions

  • Relevant fields of the command SMBv2 Find in the request direction only

  • Relevant fields of the command SMBv2 Header in both request and response directions

  • Relevant fields of the command SMBv2 IOCTL in the request direction only

  • Relevant fields of the command SMBv2 NEGOTIATE in both request and response directions

  • Relevant fields of the command SMBv2 Read in the request direction only

  • Relevant fields of the command SMBv2 Session Setup in both request and response directions

  • Relevant fields of the command SMBv2 Tree Connect in both request and response directions

  • Relevant fields of the command SMBv2 Write in the request direction only

  • FTP Action

  • FTP Banner

  • FTP File Name

  • FTP Return Code

  • FTP User Name

  • SMTP Attachments

  • SMTP Banner

  • SMTP Recipients

  • SMTP Sender

  • TELNET User Name

  • Relevant fields of the command DCERPC Bind

  • Relevant fields of the DCERPC Header in both request and response directions

  • Relevant fields of the command DCERPC Request

  • DNS OPCode

  • DNS RRName

  • DNS RRType

  • Relevant fields of the command DNS RSP Answer

  • Relevant fields of the command DNS RSP Answer Rdata

  • Relevant fields of the command DNS RSP Authority

  • Relevant fields of the command DNS RSP Authority Rdata

  • DNS RSP Header Flags

  • DNS TXID

  • DNS Type

  • HTTP CLSID

  • HTTP Host

  • HTTP Request Content Type

  • HTTP Request Filename

  • HTTP Request Method

  • HTTP Request Referer

  • HTTP Request URL

  • HTTP Response Content Type

  • HTTP Return Code

  • HTTP Server Type

  • HTTP URI

  • HTTP User-Agent

  • HTTP2 STREAM ID

  • HTTP2 Settings Enable Push (Client)

  • HTTP2/3 HTTP VERSION

  • SSL Certificate Common Name

  • SSL Server Name Indication

You can view the protocols that are enabled on the Protocols tab of the L7 Data Collection page under Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced.

You can also customize the settings for the protocols in the L7 Data Collection page. For more information, see Enable Layer 7 Data Collection for an interface or subinterface.

Filtering alerts
Filtering alerts


In addition to the column filters, there are specific sub-filters for each column. These sub-filters are based on specific values for that column. For example, the Direction column will have Inbound, Outbound, Unknown, and Bi-directional as the sub-filters. The alerts are filtered based on the selected option. Further, the Sort Ascending and Sort Descending options for each column toggles the alerts either in ascending order or descending order.

Note

Alerts cannot sorted using the Mitre Attack Details column.

Automatic refresh of alerts

Alerts in the Attack Log page can be refreshed automatically. Refer the following steps to enable or disable automatic refresh:

Note

Alerts can be refreshed manually by clicking GUID-DE8F9231-1BB5-42A7-B78B-1FDD431543A8-low.png.

  1. Click GUID-6425C44F-D89C-4196-B985-AF343EEC19F9-low.png.

    The Attack Log Settings dialog box is displayed.

    Attack Log Settings
    Attack Log Settings


    Note

    Make sure that the set time period to fetch alerts is greater than the automatic refresh interval to not lose any alert data.

  2. From the Automatic Refresh drop-down, select the refresh interval based on your requirement.

    Note

    To disable automatic refresh select Disabled from the drop-down.

  3. Click Save.

Note

When Automatic Refresh is enabled, the Attack Log page refreshes automatically every time you visit the page from some other location, such as the Dashboard tab or Threat Explorer.

Note

When you select an alert in the Attack Log page, with auto refresh enabled, the alert remains selected with the details panel still displaying the alert data though new alerts are added to the page.