To tune your deployment, analyze client rules created in Adaptive mode, and events triggered by activity on the clients.
From client rules data, you can:
See which rules are being created.
Aggregate rules to find the most common rules.
Move the rules directly to a policy for application to other clients.
From event data, you can see firewall intrusions and Trellix Global Threat Intelligence block events. Drill down to the details of an event to see:
Which process triggered the event
When the event was generated
Which client generated the event
Use Trellix ePO - On-prem queries and reports to gather information about client rules. Use the Threat Event Log to view all threat events that Trellix ePO - On-prem receives from managed systems. Analyze the event and take the appropriate action to tune the Firewall deployment to provide better response to attacks.