The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing ICAP alert details grouped by alert in the Web UI

Prev Next

The Alerts tab of the Network Security appliance list the results, grouped by alert, for web infections, infection matches, malware callbacks, and malware objects in ICAP traffic. You can drill down to identify the matched ICAP alerts that are detected as malicious for a malware event, grouped by alert. The total number of ICAP alert entries detected by the MVX engine are categorized and tracked on the Alerts tab.

An ICAP-enabled Network Security appliance supports four types of generated ICAP alerts: web infections, infection matches, malware callbacks, and malware objects.

ICAP alert entries are displayed on the Alerts tab. The default display lists entries in reverse chronological order and shows 20 results per page.

The following example displays the drill-down details of a particular malware callbackalert on ICAP traffic:

NX_alert_details_icap.png

Prerequisites

To view the ICAP alert details grouped by alert:
  1. Choose Alerts > Alerts > Alerts.

  2. Choose the ICAP alert that you want to view.

  3. To expand an entry, click the entry under any column heading.