The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Start Trellix ePO - On-prem console

Prev Next

You can view details for an endpoint by starting the Trellix ePO - On-prem console from the Attack Log itself.

Task

  1. Select Analysis → <Admin Domain Name> → Attack Log.
  2. Double-click the alert for which you want to view the details.
    The alert details panel opens.
  3. In the Summary tab under the Attaker/Target section, click the information icon next to the source or target IP address.
    The Attacker IP address – <IP address> or the Target IP address – <IP address> pop-up opens.
    Endpoint information


  4. Click ePO Threat Events and then click Open ePO console.
    The actions that you can do on the Trellix ePO - On-prem console will be based on the permissions assigned to the user credentials that you enter during Trellix ePO - On-prem server configuration.