Tags in Trellix ePO - On-prem assist you to identify and sort managed endpoints. If you are a Trellix ePO - On-prem administrator, it is crucial for you to be able to identify individual endpoints or groups of endpoints when you create tasks and queries. Tags and tag groups make this task of identification simpler. For more details about tags and how they can be best used to benefit your network, refer to chapter Using the System Tree and Tags in the Trellix ePolicy Orchestrator - On-prem 5.10.0 Product Guide.
If Trellix ePO - On-prem is integrated with Trellix IPS, which identifies endpoints by their IP addresses while Trellix ePO - On-prem identifies endpoints by a unique ID, there are likely going to be events triggered in the Manager in Trellix IPS which are suspicious or confirmed malicious. In such instances, between the time that an endpoint IP address is identified as suspicious and the time that the Trellix ePO - On-prem administrator tags the endpoint for further action, the IP address of the endpoint might have changed. To overcome this lag, the security analyst is provided a list of tags within the Manager in Trellix IPS. These tags are defined in Trellix ePO - On-prem and are communicated to the Manager in real-time.
Note
Tags can be assigned only to managed endpoints, that are endpoints running a compatible version of the Trellix Agent.