The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Dashboard tab

Prev Next

The Dashboard tab is the central interface from which all Manager interface components are available. The Dashboard tab is divided into two sections: the top menu bar and the lower monitors section.

By default, you can view the following security and operational monitors:

  • Abnormal System Health
  • Device Summary
  • Manager Summary
  • System Faults
  • Top Applications
  • Top Attacks
  • Top Attackers
  • Top Callback Activity
  • Top High-Risk Endpoints
  • Top Targets
  • Top Malware Files
  • Update Status
Dashboard tab


Note

The default time range is Last 12 hours and Automatic Refresh is set to 10 minutes.

Data viewed on the Dashboard can be customized according to your time preference using the Custom Time Period option from the refresh drop down. In addition, you can add monitors of your choice. You can also drag and drop these monitors on the Dashboard tab. The monitors display data based on the admin domain selected. Data from the child domains can also be included. In such cases, the data displayed in the monitors will also include data from the child domains. By default, the monitors display data for the root admin domain. Include child domains is selected by default.

Note

By default, all logons to the Manager display data in the dashboard for the root admin domain.

Dashboard tab view.
Name Icon Description
Hide Minimize the monitor of your choice.
Expand View the monitor of your choice.
Refresh Manually refresh the page.

Alternatively, set the automatic refresh time from the Dashboard Settings window. The default refresh time interval is 10 minutes.

Edit View the Dashboard Settings dialog.

Dashboard Settings

Use the Dashboard Settings window to further customize your Dashboard tab view.

Dashboard Settings dialog


You can perform the following tasks here:

  • Monitors— Use this option to select the monitors to view. The default category is All. Use the Operational or Security category to choose the monitors you want to view. You can also customize the data displayed in the monitors based on the admin domain and child domain. Monitors display data based on the admin domain selected from the Domain drop-down list.

    The following monitors are displayed under different categories:

    Category Monitors Description
    All View both Operational and Security monitors.
    Operational
    Abnormal System Health View the indicators of the health of Sensors.
    CPU Usage View the high CPU usage of the Sensor.
    Device Summary View the current versions of the Sensor software and signature set of the logged in domain.
    Manager Summary View the Manager details such as software version, signature set version, and others.
    Memory Usage View the high memory usage of the Sensor.
    Release Announcements View the latest updates and the current version of signature set applied to your Sensor.
    Running Tasks View the status of all the Sensors configured in the Manager.
    System Faults View the health of your device and the Manager.
    Throughput Usage View the high throughput usage of the Sensor.

    Note

    Data remains unchanged for the Manager summary, Release Announcements, and Running tasks monitors irrespective of the admin domain selected. The System Faults and Device Summary monitors display the list of all the child domains linked to the admin domain selected.

    Security
    Attack Severity Summary View the unacknowledged alerts in the database, sorted by alert severity
    Attacks Over Time View the attacks over a period of time in your network.
    Big Movers View the attacks whose frequency has increased during a selected time period.
    Top Applications (IPS) View the top applications based on attacks, bytes or connections.
    Top Applications (NTBA) View the top applications in the NTBA device based on bytes or connections.

    Note

    At least 1 NTBA appliance is required to be configured to view this monitor.

    Top Attack Subcategories View the attack subcategories in your network.
    Top Attacker Countries View the top attacker countries in your network.
    Top Attackers View the top attackers in your network.
    Top Attacks View the top attacks in your network.
    Top Callback Activity View the callback activity.
    Top Destinations (NTBA) View the top destinations based on bytes or connections.

    Note

    At least 1 NTBA appliance is required to be configured to view this monitor.

    Top Endpoint Executables (NTBA) View the top executables based on number of endpoints using them or the number of attacks they have initiated. You can filter the executables based on the device, attacks (default) or endpoints, malware confidence, and classification.

    Note

    This monitor is populated only if you have enabled McAfee EIA integration.

    Top Endpoints Using Risky URLs View the top endpoints using risky URLs in your network.
    Top Files (NTBA) View the top files based on malware confidence level.

    Note

    At least 1 NTBA appliance is required to be configured to view this monitor.

    Top High-Risk Endpoints View the high-risk endpoints of your network.
    Top Malware Files View the top malware downloads in your network. You can filter malware based on their confidence and detections (blocked, unblocked, and all).
    Top Risky URLs View the top risky URLs of your network.
    Top Sources (NTBA) View the top sources based on bytes or connections.

    Note

    At least 1 NTBA appliance is required to be configured to view this monitor.

    Top Target Countries View the top target countries in your network.
    Top Targets View the top targets in your network.
    Top URLs (NTBA) View the top URLs at risk.

    Note

    At least 1 NTBA appliance is required to be configured to view this monitor.

    Note

    The Dashboard displays only the top 10 unacknowledged alerts under each Security Monitor. To view the acknowledged alerts, go to the Attack Log page and select Acknowledged from the drop-down list. You can also select Any Alert State from the drop-down list, and the Manager will display both acknowledged and unacknowledged alerts.

  • Automatic Refresh— Use this option to set the automatic refresh time. The default time is 10 minutes. The minimum and maximum time for the automatic refresh are 1 minute and 10 minutes, respectively. For a manual refresh, select Disabled to disable the automatic refresh.
  • Layout— Use this option to customize the number of columns to be displayed on the Dashboard tab.

Note

Data displayed in the Top High-Risk Endpoints monitor is automatically refreshed by the Manager on an hourly basis. This is not user configurable.