The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

View and work with data generated by Trellix IPS

Prev Next

Once you have completed the steps in the previous sections, you are up and running. While actively monitoring network traffic, your Sensor will generate alerts and other data for traffic that is in violation of the set security policy.

The Manager processes all the information that it receives from the Sensors and presents them in a form that is readily understandable to you. The Dashboard displays the information in a graphical format, whereas the Analysis tab displays the information in a tabular format.

  • The Attack Log enables you to drill down to the details of an alert, such as what triggered the alert, when it was triggered, which Sensor detected it, the source IP address of the attack that triggered the alert, the destination IP address of the attack, and so on. You can access the Attack Log from the Analysis tab. You use the Attack Log to perform forensic analysis on the alert to help you tune the Trellix IPS system, provide better responses to attacks, and otherwise shore up your defenses. You can view the Attack Log for specific admin domains.

  • The Event Reporting page provides you detailed reports based on your alerts, and reports on your Trellix IPS configuration. You can use these reports to communicate incidents to other members of your team and to your management.

    Note

    For more information on these tools, see Reporting section.