The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Assign ePO - On-prem tags to endpoints through Threat Explorer

Prev Next

Prerequisite: To assign tags from the Manager, make sure you have enabled the Enable Endpoint Tagging? checkbox in the ePO Integration page in the Manager.

You are able to assign tags to endpoints managed by ePO - On-prem through the Threat Explorer of the Manager. These assignments reflect in ePO - On-prem in real-time.

  1. Go to Analysis → <Admin Domain Name> → Threat Explorer.

    Note

    You must select a domain in which integration with ePO - On-prem is enabled. The integration must also have endpoint tagging enabled in the Manager.

  2. Click an IP address from the Top Attackers or Top Targets panel.

    Details about the IP address appear.

    Endpoint Information tab
    Endpoint Information tab


  3. Within the Endpoint Information tab, look for the Endpoint Type.

    You are able to assign tags only to endpoints that denote the Endpoint Type as MANAGED, which means that that endpoint is managed by ePO - On-prem using the Trellix Agent.

  4. If the endpoint is managed, click the Tag (in ePO) button.

    The Tag Endpoint pop-up window appears with the IP address of the endpoint that you are about to tag, the ePO server that you have integrated with, and a drop-down list of tags you can assign. These tags are created in ePO - On-prem.

    Drop-down contains the list of tags created in ePO - On-prem
    Drop-down contains the list of tags created in ePO - On-prem


  5. Select the tag you want to assign and click Tag.

    If the assignment is successful, you receive a message stating the same.

    Tagging successful
    Tagging successful


    If you have selected an unmanaged endpoint or the tagging is unsuccessful for another reason, you receive a message stating the failure.

    Tagging fails when the endpoint is not managed by ePO - On-prem
    Tagging fails when the endpoint is not managed by ePO - On-prem


The tag is assigned to the endpoint. You will be able to view it in ePO - On-prem. To see the steps you need to follow to view the tags, see View tags in Trellix ePO - On-prem.