The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure timestamp settings

Prev Next

When an Endpoint Security (HX) user requests a triage collection based on a specific date and time, or when an automatic triage acquisition collects host endpoint information related to the time of an alert, the agent returns information for a specified window of time before and after the alert. The timestamp settings control the length of the window for the triage collection.

Timestamp settings apply only to agent URL events (URL Monitor Events) and registry key events (Reg Key Events).

You can use the Timestamp Settings tab to specify the length of time before and after the timestamp during which information is collected. Timestamp Settings can range from 0-86400 seconds. The default for both settings is 600 seconds.

Prerequisites
  • Admin access