The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Analyzing your protection

Prev Next

Analyzing your system protection is an ongoing process to improve protection and performance of your system.

Analyzing your protection enables you to determine:

  • Which threats you are facing

  • What malware was used in the attack

  • Where the threats are coming from

  • Where and when the attacks occurred

  • How often threats are found

  • Which systems are being targeted

    For example, if one system is being continuously attacked, you might move that system to a more secure part of your network and enable increased security.

  • How the attack affected the system

Protection analysis is also helpful to:

  • Create reports for IT and managers.

  • Capture information used to create scripts and queries.

  • Monitor network access time and Threat Prevention update network usage.

Dashboards and queries

Use dashboards to view information about your environment, including names and number of threats and how infection spreads through the environment. Use queries to determine where and when the attacks occurred.

For information, see the ePO - On-prem Help.

Threat Event Log

Use the Threat Event Log to determine which malware was used in the attack.

  • Threat Name and Threat Type describe what malware was used in the attack.

  • Event Description describes how the attack affected the system and which actions were taken on the threat.

  • Threat Source IP Address and Threat Target IP Address can help you determine which actions to take.

For information, see the ePO - On-prem Help.