The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Filtering Alerts and Events Using the Web UI

Prev Next
To add or modify an event filter:
  1. In the Web UI, choose Alerts > Filters.

    NX_alerts_filters.png
  2. Click the Add Filter button near the upper right corner of the screen.

    NX_alerts_filter_add.png
  3. Enter the filter information as indicated in the following table.

    Field

    Description

    Filter Name

    Name of the filter. The filter name is case-sensitive.

    Victim IP and Mask

    The address of the impacted device.

    Attacker IP and Mask

    The address from which malware was downloaded or pushed.

    Start date & end date

    Click in the field to see a calender for choosing the month, date, and year the filter starts and ends.

  4. To add the event filter, click Save.

    The event filter displays. Previously defined filters are displayed on the Alerts and Summaries tabs.

To use global filters:

The list displays the events that match the defined filter.

  1. Depending on the filter, click Alerts or Summaries.

  2. In the drop-down list, choose User Filter.

  3. Select the name of the user filter.

To delete filters:
  1. In the Filters page, select the checkbox for each filter you want to delete.

  2. Click Remove Selected Filters.

To refine filters:
filter-refine.png
  1. Open the Alerts tab.

  2. Expand the Filters group by clicking on the Filters icon filter-icon.png in the upper left corner.

  3. In the drop-down list, choose User Filters.

  4. From the expanded Filters group, select any combination of alert attributes to refine your filter:

  5. Click Apply to apply the refined filter.