The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Integration with Trellix ePolicy Orchestrator - On-prem

Prev Next

Trellix ePolicy Orchestrator - On-prem is a scalable platform for centralized policy management and enforcement of your system security products, such as anti-virus, desktop firewall, and anti-spyware applications. You can integrate   Trellix Intrusion Prevention System with   Trellix ePO - On-prem. The integration enables you to query   Trellix ePO - On-prem server from the   Trellix Intrusion Prevention System Manager for viewing details of a network host.  

The integration of   Trellix IPS with   Trellix ePO - On-prem version is based on their compatibility. The current   Trellix IPS version supports integrating with the current release of   Trellix ePO - On-prem and with some previous versions of   Trellix ePO - On-prem.  

For more information about   Trellix ePO - On-prem, see the   Trellix ePolicy Orchestrator - On-prem Product Guide. You can download the guide from   Trellix Download Server.  

Integrating   Trellix IPS and   Trellix ePO - On-prem enables you to send queries to   Trellix ePO - On-prem server to obtain details of the hosts on your network. The details that are fetched from   Trellix ePO - On-prem server include the host type, host name, user name, operating system details, top10 anti-virus events, and the details of system security products installed on the host. You can view these details in the Attack Log. If you have installed   McAfee Host IPS as part of your   Trellix ePO - On-prem installation, you can also view the last 10 Host IPS events for a specific host. These details provide increased visibility and relevance for security administrators performing forensic investigation of security events seen on the network. When you are reviewing alert details for an endpoint in Attack Log, you can view the essential host data such host name, current user, and OS version in the alert details panel.  

Consider the following scenario to understand how   Trellix IPS -Trellix ePO - On-prem integration works:  

You notice in the Attack Log that a host in your network is port scanning the other hosts. You want to know more details about the source of these attacks. You can then double-click on an alert and see the details of the source IP address. The   Trellix IPS Manager sends queries to   Trellix ePO - On-prem server. You can view the host details by clicking on the exclamation icon next to the IP address. From these details, you may realize, for example, that VirusScan (the anti-virus application) is outdated. Looking at the host name, you may also realize that it is the server that was taken off the network sometime back. Therefore, the VirusScan was not updated during this period.  

In addition to these features, you may also assign tags through the Threat Explorer of the   IPS Manager. For more information on tags, see   Tags.  

Trellix ePO - On-prem provides you the option to view   Trellix IPS data on a dashboard.  

This dashboard in   Trellix ePO - On-prem provides the following monitors:  

  • Attack Severity Summary  

  • Device Fault Summary  

  • Manager Fault Summary  

  • Top 10 Attack Destinations  

  • Top 10 Attacks  

  • Top 10 Attack Sources