The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing and analyzing flow and alert data in NI Web User Interface

Prev Next

When the integration between Trellix IPS and Trellix NI is successfully enabled, the Manager and Sensor(s) start exporting alert data, flow data, and L7 metadata to the NI which can be viewed on its Web User Interface (UI).

Note

Some screenshots and related web features referenced in this section may vary slightly from the latest NI Web UI.

If you have performed any configuration changes in the Client Group that is configured and associated with Trellix IPS, the Manager and Sensor would retrieve the changes in configuration from the NI within the time period specified for config polling, and apply those to the alerts and flow data before exporting those to the NI.

You need to login to the NI Web UI to view the alert and flow data entries exported by the Manager and Sensor(s). Perform the following steps to login to NI Web UI:

  1. After you have configured the NI’s management Ethernet interface, use the following URL on your browser and press Enter to go to the Web UI.

    https://<NI appliance IP address>

    Note

    To learn about how to set up and deploy an NI appliance, refer to Network Investigator System Administration Guide. If you wish to deploy a virtual instance of the NI appliance, refer to Network Investigator Deployment Guide.

  2. The Trellix NI login page appears.

    Provide the username and password and click the LOGIN button to access the Web UI.

    Note

    The default username is npadmin.