Best practice: Create client event summary queries

Prev Next

To display events sent from your agents to ePO - On-prem, create client event summary queries that send threat notifications to your administrator.

This example creates a client events summary query. It displays events sent from each Trellix Agent to ePO - On-prem. Items like update complete, update failed, deployment completed, or encryption started are considered client events.

For details about product features, usage, and best practices, click ? or Help.

  1. To create a client events summary query, select MenuReportingQueries & Reports.

  2. From the Queries page, click New Query.

  3. From the Query Builder, starting with the Result Types tab, click Events in the Features Group, Client Events in Result Types, then click Next.

  4. On the Chart page under Summary, click Single Group Summary Table to display a total count of all client events in the events table.

  5. To create a filter with a good human-readable description of the events, click Event Description, in the Labels are list under Threat Event Descriptions.

    Optionally, you can filter by the Event ID, which is the number that represents client event data in ePO - On-prem. For details about managed product generated event IDs listed in ePO - On-prem, see KB54677.

  6. If needed, adjust the column information based on the type that you want displayed.

    Note

    This step is not critical for the creation of the query.

  7. Click Next, the Filter page appears.

    You do not need any filtering because you want every client event returned in the database. Optionally, you can create a query based on events generated in a certain time, for example, the last 24 hours, or the last seven days.

  8. Click Run to display the query report.

  9. Click Save and type an appropriate name for the report. For example, All Client Events by Event Description.