The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Dashboard panels at-a-glance

Prev Next

On an IPS platform, the Dashboard contains display panels that give you a summary view of the Web threat prevention and threat intelligence provided by the appliance.

Panel that shows only IPS data

IPS trend

A line graph of the number of IPS alerts and the number of IPS critical events.

Data is plotted for the last 24 hours, 7 days, or 30 days.

See IPS trend.

Panel that includes a separate category for IPS alerts

What's happening

Lists the number of alerts detected in each attack category.

Each category name is a shortcut to the list of alerts counted.

Alerts are counted for the last 24 hours, 7 days, or 30 days.

See What's happening.

Panels that do not apply to IPS

Callback events

A list of the top 25 subnets in the monitored network, ranked by the following criteria:

(1) Number of callback events detected

(2) Number of infected hosts

The criteria are counted for the last 24 hours, 7 days, or 30 days.

See Callback events.

Panels that include IPS data within the statistics
Threat Level

Gauge display of an overall threat level (Low, Guarded, Elevated, High, or Severe).

The threat level is calculated based on the following Trellix measurements:

(1) Threats detected by the Network Security appliance

(2) Trellix's measurements for the selected industry and geographical location

The overall threat is derived from the two-month averages of each measurement.

See Threat level.

Critical malware detection

Pie chart of the number of hosts associated with malicious infections uniquely detected by Trellix:

▫ Hosts that triggered malware object or Web infection alerts

▫ Hosts that attempted to communicate with a botnet server.

Hosts are counted for the last 24 hours, 7 days, or 30 days.

See Critical malware detection.

Threat attacks

Pie chart of the top ten threat attack types in the monitored network.

In each category, the alert count is expressed as a percentage of the total alerts.

Attack types are counted for the last 24 hours, 7 days, or 30 days.

See Threat attacks.

Malware detection trend

Graph of malware severity over the last six months for the following sources:

▫ Malware detected by the Network Security appliance

▫ Trellix's measurements for the selected industry and geographical location

See Malware detection trends.

Top 25 infected subnets (local)

Table of the top 25 infected subnets in the monitored network, ranked by following criteria:

(1) Total number of malware events

(2) Number of unique malware types

(3) Number of infected hosts for each subnet

The criteria are counted for the last 24 hours, 7 days, or 30 days.

See Top 25 infected subnets (local).

Top malware by host and activity

Time series plot of the top 5 malware infections, ranked by either of the following criteria:

▫ Number of infected hosts

▫ Number of infections

The selected criteria is counted for the last 24 hours, 7 days, or 30 days.

See Top malware by host and activity.

Daily monitored traffic (mbps)

Multi-line graph of traffic rates detected in the monitored network.

Traffic rates are grouped by traffic type and graphed over the last 24 hours.

See Daily monitored traffic (mbps).

Service health statistics trend

Displays a graph of the aggregate health level over time (Healthy, Warning, or Critical) for the service categories that you select.

See Service health statistics trend.