The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Events, responses, and Threat Prevention

Prev Next

Configure Automatic Responses to react to threat events.

The Threat Event Log is a log file of all threat events that ePO - On-prem receives from managed systems.

In ePO - On-prem, you can define which events are forwarded to the ePO - On-prem server. To display the complete list of events in ePO - On-prem, select Menu → Configuration → Server Settings, select Event Filtering, then click Edit.

Set up a Purge Threat Event Log server task to purge the Threat Event Log periodically.

You can also view and manage Exploit Prevention events in ePO - On-prem in the Exploit Prevention Events page under Reporting.

You can use events to customize Automatic Responses.

For information about Automatic Responses and working with the Threat Event Log, see the ePO - On-prem Help.