The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate Integration Summary reports

Prev Next

The Integration Summary report provides a summary of configurations done in the Manager to integrate with other products such as, Trellix ePO - On-prem and Vulnerability Manager Configuration.

To generate an Integrated Summary Report, do the following:

  1. Click the Manager tab from the Manager Home page.
  2. Select <Admin Domain Name> → Reporting → Configuration Reports → Integration Summary.
  3. Select the Output Format.
  4. Click Submit.

The Integration Summary Report displays the following details:

  1. ePO DB Configuration
  2. Vulnerability Manager Configuration
  3. API Server
  4. Database Settings
  5. Relevance Details
  6. State
  7. Manual Scan Reports
  8. Database Settings
  9. Automated Vulnerability Manager Scan Reports
  10. Host Intrusion Prevention
  11. Telemetry Submission
  12. Technical Contact Information
  13. Global Threat Intelligence

ePO DB Configuration

The integration between the Manager and the ePO server is done with the help of an extension file. After the installation of the extension file, the detail is listed in this report and its fields are described in the following table:

Field Name Description
Admin Domain The selected admin domain for the summary report to be generated.
Endpoint Summary Queries Displays details of the Endpoint Summary Queries which can be enabled or disabled.
Endpoint Lookup Displays details of the Endpoint Queries which can be enabled or disabled.
Endpoint Tagging
Server Name or IP Address The name or the IP of the ePO server running the extension file. Note that this ePO server should have the details of the hosts covered by the admin domain. Contact your ePO administrator for the server name and IP.
Server Port Specify the HTTPS listening port on the ePO server that will be used for the Manager-ePO communication. Contact your ePO administrator for the port number.
User Name The username to be used while connecting to the ePO server. Trellix recommends you use a local ePO user account with View-only permissions.

For more information on ePO, refer to ePO documentation.

Note

If you update the IP address of ePO from the Manager in the Manager → <Admin Domain Name> → Integration → ePO Integration page, you should reboot the Manager.

Vulnerability Manager Configuration

The Vulnerability Manager Configuration settings allow the Manager to connect directly to the Vulnerability Manager engine servers and database. Enabling Vulnerability Manager scanning is the first step in configuring Vulnerability Manager from the Manager.

Note

For more information on Vulnerability Manager, refer to Vulnerability Manager documentation.

Vulnerability Manager Server Settings

Manager uses the scan engine information to view the vulnerabilities for the host after the scan is complete.

Database Settings

The second essential step in Vulnerability Manager configuration is configuring the Vulnerability Manager database settings.

Using these settings, Manager connects to the Vulnerability Manager database to get relevance information, scan configuration details, scan engine details and vulnerability data for scanned hosts. The required data is fetched directly from the Vulnerability Manager database using stored procedures specific to the Manager.

Relevance Details

Relevance analysis involves the analysis of the vulnerability relevance of real-time alerts, using the vulnerability data imported to the Manager database.

State

This field reveals the state of relevance analysis.

Manual Scan Reports

The details of the manually scanned reports are displayed in this report and its fields are described in the following table:

Field Name Description
File Name Name of the report file.
Report Type This can be plain text, XML or Trellix IPS format.
Description Description of the report file.
Scan Time Time of the Vulnerability Manager scan.
State This field shows the status of completion of the Vulnerability Manager scan. For example, the scan status can be queued, complete, retrieved etc.

Automated Vulnerability Manager Scan Reports

The details of the automated scanned reports are displayed in this report and its fields are described in the following table:

Field Name Description
Organization or Workgroup These two fields are created in the

Vulnerability Manager side that is used to scan.

Scan Name The name of the scan organization or workgroup.
Description The details of the scanned file.

Host Intrusion Prevention

The details of prevented intruders are displayed in this report and its fields are described in the following table:

Field Name Description
Name The name of the intruder.
Description The details of the intruder.

Telemetry Submission

The details of what has actually been sent to Trellix are described in the following table:

Field Name Description
Alert Data Details This field shows the details of the Alert data sent to Trellix for each attack.
Only send data for following alert severities (Filter) This field helps to configure the levels of severities.
Alert Data Summary This field shows the alert summary information sent hourly to Trellix like List of Trellix IPS attack IDs seen.
General Setup This field shows the general setup information sent daily to Trellix like Manager software version and active signature set version.
Feature Usage This field shows the feature information sent daily to Trellix like the number of default policies in use.

Technical Contact Information

The details of your contact information that are provided to the Trellix Labs are described in the following table:

Field Name Description
Send Technical contact information Technical contact information is gathered to communicate End of Life and other key milestones.
First Name The first name of the contact person.
Last Name The last name of the contact person.
Street Address The street address of the contact person.
Phone Number The phone number of the contact person.
E-mail Address The email address of the contact person.

Global Threat Intelligence

The details of private TI cloud integration are described in the following table:

Field Name Description
Private GTI Cloud Integration Displays if the private GTI cloud integration is enabled or disabled.
Private GTI Cloud Server IP Displays the server IP of the private GTI cloud.