The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Endpoint details query from the Trellix ePO - On-prem server

Prev Next

After you enable   Trellix IPS-Trellix ePO - On-prem integration at an admin domain level, you can view the details of the corresponding network endpoints using the Attack Log. If you have installed   McAfee Host Intrusion Prevention software and if the   Host Intrusion Prevention is running on the endpoint, then you can view the top 10 Host IPS events for an endpoint as well.  

Consider the following example.   My Company is the root admin domain and   HR and   Finance are its child domains.   Sensor-HR and   Sensor-Fin are the respective Sensors of the two child domains. Assume that the Manager-Trellix ePO - On-prem integration is enabled only for   Finance. For an attack detected by   Sensor-Fin, you can view the details of the source and destination endpoints from Attack Log because   Trellix ePO - On-prem integration is enabled for the   Finance admin domain.  

Note that for you to view the details, the information should be available on the   Trellix ePO - On-prem server. For example, if an attack is from outside your network, then your   Trellix ePO - On-prem server may not have any information about this source endpoint.  

Note

The   Trellix IPS extension running on   Trellix ePO - On-prem must be compatible with your current version of   Trellix IPS. Consider that you integrated   Trellix ePO - On-prem with the earlier version of   Trellix IPS, and then subsequently you upgraded   Trellix IPS. Then the integration with   Trellix ePO - On-prem might not work as expected because the   Trellix IPS extension on   Trellix ePO - On-prem is from an old installation. This extension might not be compatible with your current version of   Trellix IPS. To verify this, you can use the   Test Connection button in step 2 of the   ePO Configuration Wizard in your current Manager. If the   Trellix IPS extension is incompatible, then an error message is displayed along with the minimum required version for the extension.  

An endpoint can belong to one of the following three types:  

  • Managed Endpoints — These are endpoints currently managed by   Trellix Agent.  

  • Unmanaged Endpoints — These are endpoints recognized by   Trellix Agent but are not currently managed by any   Trellix Agent agent.  

  • Unrecognized Endpoints — These are endpoints about which   Trellix ePO - On-prem has no information. In the Attack Log, an unrecognized endpoint is represented by a series of ellipses (- - -).  

You can view the details of the source and destination endpoints in an alert. Alternatively, you can also enter the IP address and get the details from the   Trellix ePO - On-prem server. These details may enable you to troubleshoot and fix any security-related issues in those endpoints. In the Attack Log, you can view the details of managed and unmanaged endpoints but not for unrecognized endpoints.  

Note

If you modify the   Trellix ePO - On-prem server settings, re-launch the Attack Log to view the endpoint details.  

Tags

Trellix IPS now provides you the ability to assign tags to source or destination endpoints managed by   Trellix ePO - On-prem. Tags assist a security analyst in identifying endpoints that do not meet security requirements on your network. To learn more about tags and their assignment through the Manager, see   Tags.