The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Analyzing client data

Prev Next

To tune your deployment, analyze client rules created in Adaptive mode, and events triggered by activity on the clients.

  • From client rules data, you can:

    • See which rules are being created.

    • Aggregate rules to find the most common rules.

    • Move the rules directly to a policy for application to other clients.

  • From event data, you can see firewall intrusions and block events. Drill down to the details of an event to see:

    • Which process triggered the event

    • When the event was generated

    • Which client generated the event

    Use ePO - On-prem queries and reports to gather information about client rules. Use the Threat Event Log to view all threat events that ePO - On-prem receives from managed systems. Analyze the event and take the appropriate action to tune the Host Intrusion Prevention deployment to provide better response to attacks.