You can create a custom query from scratch or duplicate and change an existing query.
For details about product features, usage, and best practices, click ? or Help.
Select Menu → Reporting → Queries & Reports, then New Query. The Query wizard opens and displays the Result Types tab.
The result types are organized into groups on the left side of the page. Depending on what extensions have been checked in to ePO - On-prem, these groups vary. Most of the result types are self-explanatory, but two of the more powerful result types are Threat Events and Managed Systems. You can access these two events types as shown in the following examples.
Threat Events — In the Feature Group, select Events. Under Result Types, select Threat Events.
Managed Systems — In the Feature Group, select System Management. Under Result Types, select Managed Systems.
Choose your chart type. You have several chart types to choose from and some are more complex than others. The two simplest charts are the pie chart and the single group summary table. The pie chart compares multiple values in a graphic format, and the summary table displays a data set with over 20 results.
To create a pie chart, in the Chart type, click Pie Chart.
Choose the label or variable that you want the report to display.
Note
Many times the report does not have to return data on Trellix products. For example, you can report on the operating system versions used in your environment.
In the list, click OS Type.
Choose the columns that you want to see when you drill down on any of the variables in the report. Choosing columns is not a critical component when building a query and can be adjusted later.
Note
You can also drag-and-drop columns from left to right and add and remove columns to display.
To use the default columns, click Next.
You can filter the data that you want the query to return. You can leave the filter area blank, which returns every device in your tree, or specify the return results you are interested in. Examples of filter options include:
A group in your System Tree where the report applies. For example, a geographic location or office.
Only include laptop or desktop systems.
Only specific operating system platforms. For example, servers or workstations.
Only include systems that have an older DAT version.
Only include systems with an older version of Threat Prevention.
Only return systems that have communicated with the ePO - On-prem server in the past 14 days.
Click Next to not create any filters and display all operating system types.
Click Run to generate the report and see the results.
After you create the reports and display the output, you can fine-tune your report without starting again from the beginning. To do this, click Edit Query. Clicking Edit allows you to go back and adjust your report and run it again in seconds.
When you are done, click Save to save it permanently. Now, this query is included with your dashboards and you can run it any time.