The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Additional details for managed endpoints

Prev Next

For managed and unmanaged endpoints, you can click on the information icon next to the IP address to view additional details. These additional details are related to the point-products installed by ePolicy Orchestrator - On-premises on the endpoint.

Note

In order for these additional details to appear, you must select the Enable Endpoint Detail Queries? check-box in the Enable ePO Integration page of the Manager.

Based on the additional details and the events, you can tune the security applications on the endpoint for the best possible protection.

You can view the following details for the managed endpoint on the Endpoint Information tab:

Option

Definitions

Country

Country of the endpoint

DNS Name

DNS name of the endpoint to resolve the names to IP addresses

NetBIOS Name

NetBIOS name of the endpoint to access the host machines

Operating System

Operating system platform of the endpoint

Device Type

Type of the Sensor (for example, IPS Sensor)

MAC Address

MAC address of the endpoint

Domain/Workgroup

Domain or workgroup of the endpoint

User

Operating system user name of the endpoint

Data Source

Database tables from where information is retrieved

Trellix Agent Check-In Time

Check-in time of the Trellix Agent that communicates with the same ePolicy Orchestrator - On-premises server integrated with the admin domain

Endpoint Type

Type of endpoint:

  • UNMANAGED (No Agent) — This indicates that there is no Trellix Agent installed on the endpoint.

  • UNMANAGED (MANAGED) — This indicates that the endpoint has a Trellix Agent but there is no active communication channel between the Agent and ePO server integrated with the admin domain.

  • MANAGED — This indicates that the endpoint has a Trellix Agent and there is active communication channel between the Agent and ePO - On-prem server integrated with the admin domain. The endpoint is managed by the agent.

Installed Products

List of the installed products

Click the ePO Threat Events tab to view the latest 50 Threat Events listed in the ePolicy Orchestrator - On-premises for a selected endpoint. The information displayed under this sub-tab includes the date and time at which the threat event was generated, the ID associated with the event, the event description, event category, action taken on the event, and the type of the threat that triggered the event.

Note

Ensure that the ePolicy Orchestrator - On-premises server has the latest Trellix IPS Extension file installed. For information on how to download and install the Trellix IPS Extension, see the section Install Trellix IPS extension file in Trellix ePO - On-prem.