The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Retrieving metadata from a paired Endpoint Security Server

Prev Next

You can retrieve usernames associated with hostnames on-demand in the NDR Web UI for one IP address at a time. IP address and hostname information is automatically indexed when the NDR syncs up with the server. To configure how often indexing occurs, see Changing NDR and Endpoint Security server configuration settings after integration.

To retrieve usernames from an Endpoint Security Server:

  1. In the NDR Web UI, search for the IP address of the paired server you want to filter metadata from.

  2. Scroll to the Event Table in the Dashboard.

  3. Above the Event Table, in the button panel, click the Edit Columns button. For more information about the Event Table, see the "The Dashboard" chapter of the NDR Series User Guide.

  4. Select destinationHostName or sourceHostName from the list of filters. The option you select appears as a new column in the Event Table.

  5. In the destinationHostName or sourceHostName column, click the caret next to the hostname you want.

  6. Click getUsername. A pop-up window appears with the username associated with the hostname indexed from the server appliance.