The ePO dashboard displays the Manager alert data when integrated with Trellix IPS. When the alert data in the Manager is to be updated in the ePO dashboard, the Trellix ePO - On-prem server sends a request to the Manager server. The Manager server sends a file consisting the alert details from the Attack Log. When subsequent requests are made by the Trellix ePO - On-prem server, the Manager compiles a file again with the alert data and sends it to the Trellix ePO - On-prem server. Upon receiving the file, the Trellix ePO - On-prem server compares the new alert data with the existing alert data, and compiles a list of the difference in data. An updated list consisting of the old data and the difference in data is displayed on the dashboard. Each time the Trellix ePO - On-prem server requests for the alert data from the Manager server, alert data from the last 48 hours is compiled and sent to the Trellix ePO - On-prem server.
If you require alert data of more than 48 hours to be sent to the Trellix ePO - On-prem server, perform the following steps:
Windows based Manager server
- RDP to the Manager server.
- Go to %programfiles%\Trellix\IPS Manager\App\config\ems.properties
- In the
ems.properties file, locate the following:
epo.dashbaord.alert.data.in.days - Edit the above line as follows:
Here, the <Alert data duration> is the time period for which the alert data is compiled and sent to the Trellix ePO - On-prem server. By default, it is set to 2 days.epo.dashbaord.alert.data.in.days=<Alert data duration> - Save the changes.
Linux based Manager server
- Log in to the Manager shell.
- Execute the
edit ems.properties command.
Note
The edit command will edit the file using vi-editor. Trellix recommends you to use vi_editor command to perform editing operations on the files.
- In the
ems.properties file, locate the following:
epo.dashbaord.alert.data.in.days - Edit the above line as follows:
Here, the <Alert data duration> is the time period for which the alert data is compiled and sent to the Trellix ePO - On-prem server. By default, it is set to 2 days.epo.dashbaord.alert.data.in.days=<Alert data duration> - Save the changes.