The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Common event format

Prev Next

Most managed products now use a common event format. The fields of this format can be used as columns in the Threat Event Log.

These fields include:

  • Action Taken — Action that the product took in response to the threat.

  • Agent GUID — Unique identifier of the agent that forwarded the event.

  • DAT Version — DAT version on the system that sent the event.

  • Detecting Product Host Name — Name of the system hosting the detecting product.

  • Detecting Product ID — ID of the detecting product.

  • Detecting Product IPv4 Address — IPv4 address of the system hosting the detecting product (if applicable).

  • Detecting Product IPv6 Address — IPv6 address of the system hosting the detecting product (if applicable).

  • Detecting Product MAC Address — MAC address of the system hosting the detecting product.

  • Detecting Product Name — Name of the detecting managed product.

  • Detecting Product Version — Version number of the detecting product.

  • Engine Version — Version number of the detecting product’s engine (if applicable).

  • Event Category — Category of the event. Possible categories depend on the product.

  • Event Generated Time (UTC) — Time in Coordinated Universal Time that the event was detected.

  • Event ID — Unique identifier of the event.

  • Event Received Time (UTC) — Time in Coordinated Universal Time that ePO - On-prem received the event.

  • File Path — File path of the system which sent the event.

  • Host Name — Name of the system which sent the event.

  • IPv4 Address — IPv4 address of the system which sent the event.

  • IPv6 Address — IPv6 address of the system which sent the event.

  • MAC Address — MAC address of the system which sent the event.

  • Network Protocol — Threat target protocol for network-homed threat classes.

  • Port Number — Threat target port for network-homed threat classes.

  • Process Name — Target process name (if applicable).

  • Server ID — Server ID that sent the event.

  • Threat Name — Name of the threat.

  • Threat Source Host Name — System name from which the threat originated.

  • Threat Source IPv4 Address — IPv4 address of the system from which the threat originated.

  • Threat Source IPv6 Address — IPv6 address of the system from which the threat originated.

  • Threat Source MAC Address — MAC address of the system from which the threat originated.

  • Threat Source URL — URL from which the threat originated.

  • Threat Source User Name — User name from which the threat originated.

  • Threat Type — Class of the threat.

  • User Name — Threat source user name or email address.