Trellix ePolicy Orchestrator - On-premises is a scalable platform for centralized policy management and enforcement of your system security products, such as anti-virus, desktop firewall, and anti-spyware applications. You can integrate Trellix Intrusion Prevention System with ePO - On-prem. The integration enables you to query ePO - On-prem server from the Trellix Intrusion Prevention System Manager for viewing details of a network host.
The integration of Trellix IPS with ePO - On-prem version is based on their compatibility. The current Trellix IPS version supports integrating with the current release of ePO - On-prem and with some previous versions of ePO - On-prem.
For more information about ePO - On-prem, see the Trellix ePolicy Orchestrator - On-prem Product Guide. You can download the guide from Trellix Download Server.
Integrating Trellix IPS and ePO - On-prem enables you to send queries to ePO - On-prem server to obtain details of the hosts on your network. The details that are fetched from ePO - On-prem server include the host type, host name, user name, operating system details, top10 anti-virus events, and the details of system security products installed on the host. You can view these details in the Attack Log. When you are reviewing alert details for an endpoint in Attack Log, you can view the essential host data such host name, current user, and OS version in the alert details panel.
Consider the following scenario to understand how Trellix IPS -ePO - On-prem integration works:
You notice in the Attack Log that a host in your network is port scanning the other hosts. You want to know more details about the source of these attacks. You can then double-click on an alert and see the details of the source IP address. The Trellix IPS Manager sends queries to ePO - On-prem server. You can view the host details by clicking on the exclamation icon next to the IP address. From these details, you may realize, for example, that VirusScan (the anti-virus application) is outdated. Looking at the host name, you may also realize that it is the server that was taken off the network sometime back. Therefore, the VirusScan was not updated during this period.
In addition to these features, you may also assign tags through the Threat Explorer of the IPS Manager. For more information on tags, see Tags.
ePO - On-prem provides you the option to view Trellix IPS data on a dashboard.
This dashboard in ePO - On-prem provides the following monitors:
Attack Severity Summary
Device Fault Summary
Manager Fault Summary
Top 10 Attack Destinations
Top 10 Attacks
Top 10 Attack Sources