The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Finding malware events per subnet: best practice

Prev Next

Finding threats by subnet IP address shows you whether a certain group of users needs process changes or additional protection on your managed network.

For example, if you have four subnets, and only one subnet is continuously generating threat events, you can narrow down the cause of those threats. Perhaps users on that subnet have been sharing infected USB drives.