The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing infection summaries using the Web UI

Prev Next
To display the Malware view:
  1. In the Web UI, choose Alerts > Summaries.

    The Summaries page appears.

  2. In the drop-down list, choose Malware.

    The Malware Summary page appears.

    NX_AlertsSummaries_Scap.png

    By default, the Events filter is set to Hide Acknowledged and this page shows information about unacknowledged events only. To show information about acknowledged events only, select Show Acknowledged. To view both unacknowledged events and acknowledged events, select All. Acknowledged alerts are identified by a blue bar on the right side of the Host field.

    filter_events_acknowledged.png

    Information for each infection is described in the following table.

    Field

    Description

    Malware

    Type of infection that is involved in the attack. For information about the event types, see Alerts and the infection life cycle.

    Alerts

    Number of events involved in the attack.

    Sources

    Number of sources involved in the attack.

    Targets

    Number of targeted hosts involved in the attack.

    Most Recent

    Most recent event that is involved in the attack.

    Last Event

    Last event that is involved in the attack.

  3. (Optional) Export a PDF file of the results from the Malware view. The PDF file contains only the content that is visible on the page. For example, if an item on the page is not expanded, the details about that item are displayed and will not be included in the PDF output. To export a PDF, expand sections to show the information you want to capture. Choose the processing time as standard, extra, or heavy. The default processing time is standard. Click Print PDF at the top right-side of the page.

  4. To view filtered events, click the number link.

    The events are organized by the following infection types:

    Note

    If the Network Security appliance is configured for inline operation, and if the numeric link is a callback, the Filtered Events details will display the blocking action that was taken.

    • Binary Analysis

    • CnC SigMatch

    • Domain Match

    • Infection Match

    • Web Infection

  5. In the Filtered Events page, click the arrow located to the left of an event type. The view expands to display the event details. For information about field descriptions for filtered events, see Monitoring malware and callback activity using the Web UI.

To display the Charts view:

By default, the Charts filter is set to Hide Acknowledged and this page shows information about all unacknowledged events. To include acknowledged events, select All. To show only acknowledged events, select Show Acknowledged.

  1. In the Web UI, choose Alerts > Summaries.

    The Summaries page appears.

  2. In the drop-down list, choose Charts.

    The Charts Summary page appears.

    NX_SummariesCharts_scap.png

    By default, the Events field is set to All and this page shows information about all events. To view information about unacknowledged alerts only, select Hide Acknowledged. To view information about acknowledged events only, select Show Acknowledged.

    The top infected hosts and top malware events are displayed in a bar chart. Charts are described in the following table.

    Chart

    Description

    Top Infected Hosts

    Displays a bar for the total number of malware events. Color-coded segments represent the different malware event types. For example, the gray segments in the figure above represent the number of malware-binary events.

    Top Malware Events

    Displays pair of bars for each type of malware event. The upper bar represents the total number of events of that type, and the lower bar represents the number of infected hosts.

  3. To display only data from the last two weeks, click Show last 2 weeks.

  4. To display all the time periods, click Show all weeks.

    By default, all available time periods are displayed.

  5. (Optional) Export a PDF file of the results from the Charts view. The PDF file contains only the content that is visible on the page. For example, if an item on the page is not expanded, the details about that item are displayed and will not be included in the PDF output. To export a PDF, expand sections to show the information you want to capture. Choose the processing time as standard, extra, or heavy. The default processing time is standard. Click Print PDF at the top right-side of the page.

To display the greylists charts view:

Note

Greylists must be enabled by means of the CLI. For information about enabling greylists, see Enabling greylists using the CLI .

  1. In the Web UI, choose Alerts > Summaries.

    The Summaries page appears.

  2. In the drop-down list, choose Greylist Charts.

    The Greylist Charts Summary page appears.

    By default, the Events field is set to All and the chart shows information about both unacknowledged events and acknowledged events. To view information about unacknowledged events only, select Hide Acknowledged. To view information about acknowledged events only, select Show Acknowledged.

Greylist charts are described in the following table.

Chart

Description

Greylist Matches

Displays the 15 greylists with the largest number of total matches. The total matches are divided into Not Analyzed and Malicious counts. The greylist type (URL or IP) is also displayed.

Greylist Efficiency %

Displays the efficiency for the greylist based on a time interval of either 24 hours or 2 weeks. The efficiency is the total number of malicious matches divided by the total number of matches, shown as a percentage. Click the eye icon to the right of a greylist name on the floating legend to either show or hide the graph for that greylist.

To display the Greylists Table view:

Note

Greylists must be enabled by using the CLI. For information about enabling greylists, see Enabling greylists using the CLI .

  1. In the Web UI, choose Alerts > Summaries.

    The Summaries page appears.

  2. In the drop-down list, choose Greylist Table.

    The Greylist Table Summary page appears.

    By default, the Events field is set to All and the chart shows information about both unacknowledged events and acknowledged events. To view information about unacknowledged events only, select Hide Acknowledged. To view information about acknowledged events only, select Show Acknowledged.

The greylist table fields are described in the following table.

Field

Description

Greylist

Name of the greylist file.

Type

IP or URL.

Priority Boost

Value for the user-assigned priority for the greylist (0.0-25.0). A high priority can be assigned to URLs or IP addresses that have a high probability of hosting malware and a low priority to URLs or IP addresses that are not likely to host malware.

Total Match

Total number of occurrences that match the greylist URLs or IP addresses.

Malicious

Number of occurrences that have been processed and match the URLs or IP addresses in the greylist file.

Not Analyzed

Number of occurrences that have not yet been processed.

Efficiency %

Total number of malicious matches divided by the total number of matches, shown as a percentage.

To display the Treemaps view:

Click an individual box to display details for that signature or network.

Field

Description

By Signatures

Each box represents a malware event type, identified by name.

By Hosts

Each box represents an infected network, identified by the IP address.

Subnet Mask

Select the subnet mask for the treemap.

Timeframe

Specify the time period of the display.

Show events by

Select the area or color button to highlight the significance of the events by area (larger area indicates more events) or depth of color (darker color indicates more infections).

  1. In the Web UI, choose Alerts > Summaries.

    The Summaries page appears.

  2. In the drop-down list, choose Treemaps.

    The Treemaps Summary page represents the number and the severity of the infections with different box sizes and colors.

    NX_SummariesTreemaps_scap.png

    By default, the Events field is set to Hide Acknowledged and the treemap shows information about unacknowledged events only. To show information about acknowledged events only, select Show Acknowledged. To view both unacknowledged events and acknowledged events, select All.

    filter_events_acknowledged_OLD_Treemaps.png

    You can view the treemap by signatures or hosts using the controls at the top of the page. Fields are described in the following table.