The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing alerts with blocked traffic using the Web UI

Prev Next

This procedure describes how to view alerts for Infection Match and Malware Callback events with blocked traffic.

Prerequisites

  • Monitor, Analyst, Operator, or Admin access to the Network Security appliance Web UI.

To view blocked-by-proxy alerts:
  1. Go to the Alerts > Alerts > Hosts page or the Alerts > Alerts > Alerts page. Alerts for blocked traffic are marked with a Blocked badge in the Badges column.

    Note

    To list all Blocked alerts together, you can filter or sort the list of alerts on the Badges column.

    After an Infection Match or a Malware Callback event is detected, there can be a delay of up to 30 seconds before the appliance determines whether traffic was blocked and the Web UI displays the Blocked badge. By default, the blocked-by-proxy detection feature waits up to 10 seconds for confirmation that the event was blocked by the Web proxy.

  2. To display alert details, expand the entry by clicking the icon in the first column of the alert entry. The detailed information includes a Blocking Action message that shows that the traffic was blocked by the Web proxy. For more information, see Badge for Blocked Traffic Events.