The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What's happening

Prev Next

This panel lists an alert count for each attack category detected on the monitored network during the past day, week, or month. By default, the panel displays alert counts for the past 24 hours. The alert counts exclude acknowledged alerts. The following is an example of a default view of the What's Happening panel.

scap_ips_dashboard_3_Whats_Happening.png

You can use the controls at the bottom of the panel to adjust the data displayed:

  • Include or exclude acknowledged alerts

  • Change the period of time covered by the display

The attack category names are shortcuts to the Alerts tab, the MVX‑Correlated IPS Events page, or the Alerts > Riskware page.

scap_ips_dashboard_to_ips_events.png

/docs/ips-events

For information about the Alerts tab, see Alerts grouped by attack rule names. For information about the IPS Events page, see About the IPS events page. For information about the Alerts > Riskware page, go to the Network Security User Guide.

The following table describes attack categories that can appear in the What's Happening panel. Click the attack category name to view the individual alerts in that category.

Icon

Attack category

To view individual MVX‑correlated alerts

icon_ips_dashboard_whats-happening_apt-attacks.png

Advanced Persistent Threats

Click APT Attacks.

The Alerts page lists entries that match one of the following value in the Malware column:

● .APT.

● _APT_

icon_ips_dashboard_whats-happening_new-global-threats.png

Attacks not seen before

Click Not Seen Before.

The Alerts page lists entries that match one of the following values in the Malware column:

● Exploit.Browser

● Malware.ZerodayMatch

● Malware.Binary

● Malware.ZerodayCallback

● ^DTI.Callback

icon_ips_dashboard_whats-happening_hosts-infected-by-malware-traffic.png

Clients infected

Click Hosts Infected by Web Traffic.

The Alerts page list entries that match the following value in the Type column:

● Web Infection

icon_ips_dashboard_whats-happening_malicious-domain-attacks.png

Malicious domain matches

Click Malicious domain match.

The Alerts page lists entries that match the following value in the Type column:

● Domain Match

icon_ips_dashboard_whats-happening_malware-objects.png

Malware objects downloaded

Click Malware Objects,

The Alerts page lists entries that match the following value in the Type column:

● Malware Object

icon_ips_dashboard_whats-happening_ips-alerts.png

MVX-Correlated IPS Events

Click MVX Correlated IPS Events.

The IPS Events page lists entries that have an MVX badge.

note.png

This attack category applies to IPS platforms only.

icon_ips_dashboard_whats-happening_riskware-alerts.png

Riskware Alerts

Click Riskware Alerts.

The Riskware page lists entries that match the following value in the Type column:

● Riskware Object

The following examples are two What's Happening panels for the same data. In the first example, the default display criteria do not select alerts in any attack category. In the second example, including acknowledged alerts and expanding the time frame causes the What's Happening panel to select alerts in five attack categories.

scap_ips_dashboard_3_Whats_Happening_compare.png