The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sorting and filtering alerts

Prev Next

If you have a large SOC team, or there are a large number of alerts in your environment, you must be able to sort and filter the alerts table to maximize efficiency. You can click specific column headings to sort the alerts table, or type the name of an alert in the filter bar above the table, or filter columns with the filter icon (HelixConnect-filter.png) in the column header. Click one of the drop down menus above the alerts table to filter by time range, assignee, or status. Federated customers can also filter the table by tenant ID.

You can use row grouping to sort the data in the alerts table to make it easier to manage and analyze. Where available, in the column header, select More Options more-options.png > Group by. Row groups are created for each unique value in the column with rows containing alerts with that value. For example, if you group by the Severity column the table creates a row group for each severity, which contain all the alerts with that severity.

Note

If you sort the table in this way, you cannot take any bulk actions on the alerts.

Use cases for this feature include:

  • As a SOC leader, group by the Assigned To and Status columns to easily see workloads across the team and to track progress. Or, group by the Severity and Rule ID columns to see which rules are generating high priority alerts and assess rule performance.

  • As a SOC analyst, group by the Severity column so you can focus on the most critical alerts first.

  • If you are a federated user, group by the Tenant and Severity columns to quickly get an overview of alerts in all the tenants you manage.