The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Analyzing client data

Prev Next

To tune your deployment, analyze client rules created in Adaptive mode, and events triggered by activity on the clients.

  • From client rules data, you can:

    • See which rules are being created.

    • Aggregate rules to find the most common rules.

    • Move the rules directly to a policy for application to other clients.

  • From event data, you can see firewall intrusions and Trellix Global Threat Intelligence block events. Drill down to the details of an event to see:

    • Which process triggered the event

    • When the event was generated

    • Which client generated the event

    Use ePO - On-prem queries and reports to gather information about client rules. Use the Threat Event Log to view all threat events that ePO - On-prem receives from managed systems. Analyze the event and take the appropriate action to tune the Firewall deployment to provide better response to attacks.