Trellix ePolicy Orchestrator - On-prem is a scalable platform for centralized policy management and enforcement of your system security products, such as anti-virus, desktop firewall, and anti-spyware applications. You can integrate Trellix Intrusion Prevention System with Trellix ePO - On-prem. The integration enables you to query Trellix ePO - On-prem server from the Trellix Intrusion Prevention System Manager for viewing details of a network host.
The integration of Trellix IPS with Trellix ePO - On-prem version is based on their compatibility. The current Trellix IPS version supports integrating with the current release of Trellix ePO - On-prem and with some previous versions of Trellix ePO - On-prem.
For more information about Trellix ePO - On-prem, see the Trellix ePolicy Orchestrator - On-prem Product Guide. You can download the guide from Trellix Download Server.
Integrating Trellix IPS and Trellix ePO - On-prem enables you to send queries to Trellix ePO - On-prem server to obtain details of the hosts on your network. The details that are fetched from Trellix ePO - On-prem server include the host type, host name, user name, operating system details, top10 anti-virus events, and the details of system security products installed on the host. You can view these details in the Attack Log. If you have installed McAfee Host IPS as part of your Trellix ePO - On-prem installation, you can also view the last 10 Host IPS events for a specific host. These details provide increased visibility and relevance for security administrators performing forensic investigation of security events seen on the network. When you are reviewing alert details for an endpoint in Attack Log, you can view the essential host data such host name, current user, and OS version in the alert details panel.
Consider the following scenario to understand how Trellix IPS -Trellix ePO - On-prem integration works:
You notice in the Attack Log that a host in your network is port scanning the other hosts. You want to know more details about the source of these attacks. You can then double-click on an alert and see the details of the source IP address. The Trellix IPS Manager sends queries to Trellix ePO - On-prem server. You can view the host details by clicking on the exclamation icon next to the IP address. From these details, you may realize, for example, that VirusScan (the anti-virus application) is outdated. Looking at the host name, you may also realize that it is the server that was taken off the network sometime back. Therefore, the VirusScan was not updated during this period.
In addition to these features, you may also assign tags through the Threat Explorer of the IPS Manager. For more information on tags, see Tags.
Trellix ePO - On-prem provides you the option to view Trellix IPS data on a dashboard.
This dashboard in Trellix ePO - On-prem provides the following monitors:
Attack Severity Summary
Device Fault Summary
Manager Fault Summary
Top 10 Attack Destinations
Top 10 Attacks
Top 10 Attack Sources