The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Manager software

Prev Next

The Manager software has a web-based user interface for configuring and managing Trellix IPS. Users connect to the Manager server from a supported client using a supported browser, the details of which are in the Trellix Intrusion Prevention System Installation Guide. The Manager functions are configured and managed through a GUI application, which includes complementary interfaces for alerts, system status, system configuration, report generation, and fault management. All interfaces are logically parts of the Manager program.

The Manager user interface has five main tabs:

  • Dashboard — The Dashboard is the first page displayed after the user logs on to the system. Options available within the page are determined by the current user's assigned roles. The Dashboard enables you to view all the critical information regarding Trellix IPS deployment in the same page. The Dashboard is very user configurable. You can configure the information that you want to view, the timeframe for which you want to view the information, the frequency with which the Dashboard must auto-refresh, and so on. All these information can be customized to view for a particular admin domain. You can select the admin domain from the Domain drop-down list to display data for the selected admin domain.

    Some of the information displayed on the dashboard includes:

    • Release announcements
    • Information regarding the frequently seen malicious activities on your network. This includes things, such as the most downloaded malware, most callback activity, the most targeted hosts, the most detected attack and so on.
    • System faults of Trellix IPS components which show whether all those are functioning properly, the number of unacknowledged alerts in the system, and the configuration options available to the current user
    • Manager-related details, such as the version, signature set version, users logged on to the Manager, and so on
    • Information like whether the devices are up-to-date
  • Analysis — This tab presents the options using which you can view the granular details of all the malicious activities on your network. The intention here is to provide you all the critical information needed for further analysis for the selected admin domain.

    One of the key options on the Analysis tab is the Attack Log, which displays the alerts triggered by the Sensors. The Attack Log page displays the hosts detected on your network as well as the detected security events that violate your configured security policies. The Attack Log provides powerful drill-down capabilities to enable you to see all of the details on a particular alert, including its type, source and destination addresses, and packet logs where applicable.

  • Policy — All the major features in Trellix IPS are policy based. For example, to block exploit and recon attacks, you use the IPS and the recon policies; for Firewall, you use the Firewall policies; for QoS, you use the QoS policies and so on. The Policy tab provides the options to manage all these policies and other related functionality.
  • Devices — You can use the same instance of the Manager to manage both the physical and virtual devices. The Devices tab provides all system configuration options, and facilitates adding and configuration of your devices - Sensors, NTBA Appliances, HA pairs of Sensors, etc. This tab provides configuration options on per device basis as well. Access to various activities is based on the current user's role(s) and privileges, administrative domains, attack policies and responses, user-created signatures, and system reports.
  • Manager — This tab provides the configuration options related to the Manager software. This includes managing administrative domains, users, and roles, downloading signature sets and other software such as Sensor software, integrating the Manager with other Trellix products, maintenance activities such as database backups, and so on.

Other key features of Manager include:

  • Integration with other Trellix products — You can integrate Trellix IPS with other Trellix products to provide you with a comprehensive network security solution.
    • Trellix ePolicy Orchestrator - On-prem — Trellix ePolicy Orchestrator - On-prem (ePO) is a scalable platform for centralized policy management and enforcement of your system security products, such as anti-virus, desktop firewall, and anti-spyware applications. You can integrate Trellix IPS with Trellix ePO - On-prem 5.0 and above. The integration enables you to query the Trellix ePO - On-prem server from the Manager for viewing details of a network host.
    • McAfee® Host Intrusion Prevention — McAfee Host Intrusion Prevention (HIP) is a host-based intrusion prevention system that prevents external and internal attacks on the hosts in the network, thus protecting services and applications running on them. Trellix IPS integrates with McAfee Host Intrusion Prevention version 7.0 and above.
    • McAfee® Vulnerability Manager — Vulnerability assessment is an automated process of proactively identifying vulnerabilities of computing systems in a network to determine security threats. Trellix IPS integrates with McAfee Vulnerability Manager to enable import of the Vulnerability Manager scan data into the Manager, to provide automated updating of IPS-event data relevancy. You can view the scan details in the Attack Log page. This provides a simple way for security administrators to access near real-time updates of host vulnerability details, and improved focus on critical events. You can initiate an on-demand scan for an IP address from the Threat Explorer.
    • Trellix Global Threat Intelligence — Trellix Global Threat Intelligence is a global threat correlation engine and intelligence base of global messaging and communication behavior including reputation, volume, trends, email, web traffic and malware. By having Trellix Global Threat Intelligence integration, you can report, filter, and sort hosts involved in attacks based on their network reputation and the country of the attack origin.

    For more information on all the above mentioned integration options, see Trellix Intrusion Prevention System Integration Guide.

  • Integration with third-party products — Trellix IPS enables the use of multiple third-party products for analyzing faults, alerts, and generated packet logs.
    • Fault/Alert forwarding and viewing — You have the option to forward all fault management events and actions, as well as IPS alerts to a third-party application. This enables you to integrate with third-party products that provide trouble ticketing, messaging, or any other response tools you may want to incorporate. Fault and/or alert forwarding can be sent to the following ways:
      • Syslog Server — forward IPS alerts and system faults
      • SNMP Server (NMS) — forward IPS alerts and system faults
      • Java API — forward IPS alerts
    • Packet log viewing — View logged packets/flows using third-party software, such as Wireshark.