Suppressed alerts are displayed on the Settings > Suppressed Alerts page. You can manage the suppressed MD5s and URLs in the following ways:
Note
When the Classic edition Network Security appliance is converted to SmartVision edition, the Suppressed Alerts option is not available under Settings.
View the list of all suppressed MD5s and URLs.
Stop suppressing alerts for an MD5 or URL that was either suppressed in error or thatTrellix determined to be malicious. The alerts attached to the associated MD5 or URL will then be restored on the Alerts page.
Resolve alerts thatTrellix determined to be false positives. Do this only afterTrellix confirms they are false positives and you apply the security content update in which they are addressed.
Locate the Alert ID, LMS ID, and Suppression Time. You need to provide this information when you contact Customer Support about a specific alert.
Download the alert details package so you can send it to Customer Support to investigate. This package is available for download if your appliance has a one-way SECURITY_CONTENTS license.
View details about a suppressed alert.
See Alert suppression for the effects of stopping and resolving suppressed MD5s and URLs.
Note
On a Network Security appliance managed by a Central Management System appliance, the Suppressed Alerts page is read-only.
Log in to the Web UI as a user with Admin, Analyst, or Monitor access.
Click Settings > Suppressed Alerts. The suppressed MD5s and URLs are listed on the Suppressed Alerts page

Log in to the Web UI as a user with Admin or Analyst access.
Select the MD5 or URL that you want to stop suppressing. To select all of them, select the checkbox at the top of the list.
Click UNSUPPRESS.
Click OK.
Log in to the Web UI as a user with Admin or Analyst access.
Select the MD5 or URL that you want to resolve. To select all of them, select the checkbox at the top of the list.
Click RESOLVE.
Caution
Do not resolve alerts until theTrellix Security Content team determines that they are false positives and updates its security content. Apply the latest security content update to your appliance, and then resolve the alerts.
Log in to the Web UI as a user with the Admin, Analyst, or Monitor role.
Click Settings > Suppressed Alerts. The suppressed MD5s and URLs are listed on the Suppressed Alerts page.
Click the link in the Count column. (If the appliance is managed by a Central Management System appliance, the link is available only on the managed appliance.)
Note
The number in the Count column represents the number of events that matched the MD5 or URL, both before and after the MD5 or URL was suppressed.
The page displays the same details about the alert that were available from the Alerts page before the alert was suppressed.
Log in to the Web UI as a user with Admin, Analyst, or Monitor access.
Click the Download XML link on the Suppressed Alerts page. A ZIP file containing the package is downloaded to your computer.
Note
This link is available only if your appliance has a one-way CONTENT_UPDATES license. For details, see Sharing the alert details package with Trellix.