The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Understanding alert activity using the Alert Timeline

Prev Next

Providing alert information in the form of only text can make it difficult to both understand the order of activity and see the significance of each event. The Alert Timeline provides a visual graph to help you understand each event in the alert in chronological order. Above the timeline you can see how many alerts and events there are, as well as their severity, and any attributes that link the events or alerts. Hover over the icons in the Actions pane to see what response actions have been taken on the alert.

The timeline dynamically adapts to the alert's source, and each node displays the most relevant information. For example, the hostname, devicename, and IP address for endpoint alerts, or the sender's email, domain, and attachment type for email alerts. Where available, you can see Wise Investigative Tips which are a list of questions with associated search queries that enrich the alert with contextual information. Expand each tip to see the results of the search query, and click the search icon Helix_search.png to add that query to the search bar.

Each node also shows important contextual information to help you better understand and investigate the alert. You can see the rule that triggered the alert, as well as the conditions that matched, and the associated MITRE technique. Select each event to open a side panel to see the event details, raw data, rule details such as the match condition, and any notes analysts have written on the event.

To provide more efficient operation, alerts are combined when a rule generates multiple alerts over a defined period of time. For example, the first time a rule triggers an alert, it generates a unique alert. Instead of generating multiple new alerts, new events are added to the unique alert for each subsequent trigger of the same rule over the defined period of time. This reduces the volume of alerts, while ensuring analysts maintain visibility of all relevant events.