After you enable Trellix IPS-Trellix ePO - On-prem integration at an admin domain level, you can view the details of the corresponding network endpoints using the Attack Log. If you have installed McAfee Host Intrusion Prevention software and if the Host Intrusion Prevention is running on the endpoint, then you can view the top 10 Host IPS events for an endpoint as well.
Consider the following example. My Company is the root admin domain and HR and Finance are its child domains. Sensor-HR and Sensor-Fin are the respective Sensors of the two child domains. Assume that the Manager-Trellix ePO - On-prem integration is enabled only for Finance. For an attack detected by Sensor-Fin, you can view the details of the source and destination endpoints from Attack Log because Trellix ePO - On-prem integration is enabled for the Finance admin domain.
Note that for you to view the details, the information should be available on the Trellix ePO - On-prem server. For example, if an attack is from outside your network, then your Trellix ePO - On-prem server may not have any information about this source endpoint.
Note
The Trellix IPS extension running on Trellix ePO - On-prem must be compatible with your current version of Trellix IPS. Consider that you integrated Trellix ePO - On-prem with the earlier version of Trellix IPS, and then subsequently you upgraded Trellix IPS. Then the integration with Trellix ePO - On-prem might not work as expected because the Trellix IPS extension on Trellix ePO - On-prem is from an old installation. This extension might not be compatible with your current version of Trellix IPS. To verify this, you can use the Test Connection button in step 2 of the ePO Configuration Wizard in your current Manager. If the Trellix IPS extension is incompatible, then an error message is displayed along with the minimum required version for the extension.
An endpoint can belong to one of the following three types:
Managed Endpoints — These are endpoints currently managed by Trellix Agent.
Unmanaged Endpoints — These are endpoints recognized by Trellix Agent but are not currently managed by any Trellix Agent agent.
Unrecognized Endpoints — These are endpoints about which Trellix ePO - On-prem has no information. In the Attack Log, an unrecognized endpoint is represented by a series of ellipses (- - -).
You can view the details of the source and destination endpoints in an alert. Alternatively, you can also enter the IP address and get the details from the Trellix ePO - On-prem server. These details may enable you to troubleshoot and fix any security-related issues in those endpoints. In the Attack Log, you can view the details of managed and unmanaged endpoints but not for unrecognized endpoints.
Note
If you modify the Trellix ePO - On-prem server settings, re-launch the Attack Log to view the endpoint details.
Tags
Trellix IPS now provides you the ability to assign tags to source or destination endpoints managed by Trellix ePO - On-prem. Tags assist a security analyst in identifying endpoints that do not meet security requirements on your network. To learn more about tags and their assignment through the Manager, see Tags.