The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Additional details for managed endpoints

Prev Next

For managed and unmanaged endpoints, you can click on the information icon next to the IP address to view additional details. These additional details are related to the point-products installed by   ePolicy Orchestrator - On-prem on the endpoint.  

Note

In order for these additional details to appear, you must select the   Enable Endpoint Detail Queries? check-box in the   Enable ePO Integration page of the Manager.  

If you have installed   Host Intrusion Prevention and it is running on the endpoint, you can view the last 10   Host Intrusion Prevention events in the endpoint. Note that the last 10 events displayed are sorted based on their severity levels.  

Note

A Host Intrusion Prevention event is an alert generated by Host Intrusion Prevention regarding an activity on the endpoint. For more information, see the related documentation.  

Based on the additional details and the events, you can tune the security applications on the endpoint for the best possible protection.  

You can view the following details for the managed endpoint on the   Endpoint Information tab:  

Option  

Definitions  

Country  

Country of the endpoint  

DNS Name  

DNS name of the endpoint to resolve the names to IP addresses  

NetBIOS Name  

NetBIOS name of the endpoint to access the host machines  

Operating System  

Operating system platform of the endpoint  

Device Type  

Type of the Sensor (for example, IPS Sensor)  

MAC Address  

MAC address of the endpoint  

Domain/Workgroup  

Domain or workgroup of the endpoint  

User  

Operating system user name of the endpoint  

Data Source  

Database tables from where information is retrieved  

Trellix Agent Check-In Time  

Check-in time of the   Trellix Agent that communicates with the same   ePolicy Orchestrator - On-prem server integrated with the admin domain  

Endpoint Type  

Type of endpoint:  

  • UNMANAGED (No Agent) — This indicates that there is no   Trellix Agent installed on the endpoint.  

  • UNMANAGED (MANAGED) — This indicates that the endpoint has a   Trellix Agent but there is no active communication channel between the Agent and   ePolicy Orchestrator - On-prem server integrated with the admin domain.  

Installed Products  

List of the installed products  

Click the   ePO Threat Events tab to view the latest   50 Threat Events listed in the   ePolicy Orchestrator - On-prem for a selected endpoint. The information displayed under this sub-tab includes the date and time at which the threat event was generated, the ID associated with the event, the event description, event category, action taken on the event, and the type of the threat that triggered the event.  

Note

Ensure that the   ePolicy Orchestrator - On-prem server has the latest   Trellix IPS Extension file installed. For information on how to download and install the   Trellix IPS Extension, see the section   Install Trellix IPS extension file in Trellix ePO - On-prem.