The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Start ePO - On-prem console

Prev Next

You can view details for an endpoint by starting the ePO - On-prem console from the Attack Log itself.

Steps:

  1. Select Analysis → <Admin Domain Name> → Attack Log.

  2. Double-click the alert for which you want to view the details.

    The alert details panel opens.

  3. In the Summary tab under the Attaker/Target section, click the information icon next to the source or target IP address.

    The Attacker IP address – <IP address> or the Target IP address – <IP address> pop-up opens.

    Endpoint information
    Endpoint information


  4. Click ePO Threat Events and then click Open ePO console.

    The actions that you can do on the ePO - On-prem console will be based on the permissions assigned to the user credentials that you enter during ePO - On-prem server configuration.