Alerts are asynchronous notifications sent when a system event or attack triggers the IPS. When a packet violating your enforced security policies is detected, the Sensor compiles information about the offending packet and sends the information to the Manager in the form of an alert. An alert contains a variety of information on the incident that triggered it—such as the type of attack, its source and destination IP addresses, its source and destination ports, as well as security analysis information (performed by the Sensor) such as attack severity and type. You can use this information to perform forensic analysis on the alert—that is, careful investigation to determine its cause and how to prevent others of its kind.
An attack is a violation of set policy parameters. An alert is one or more attack instances. In many cases, an alert represents a single detected attack. A multi-attack alert is generated when multiple instances of identical attacks (same attacker IP, target IP, and specific attack) are detected within a two minute period; data for all attacks is throttled into one alert instance, however, you can also choose to configure for how many of each throttled attacks you want to see an individual alert.
Trellix IPS stores alerts in the Manager server database until you delete them. You can view your alerts in the Manager using the Analysis → <Admin Domain Name> → Attack Log page.
For more information, refer to Configure alert suppression with packet log response topic in IPS Administration section.