Create custom queries using Trellix ePO - On-prem query system and reuse them in dashboard monitors and report sections.
We provide an overview on using Trellix ePO - On-prem query capabilities for gathering TIE server information. For more details, see Trellix ePO - On-prem online Help.
The TieServerSchema retrieves information about Enterprise reputation, files, and certificates from the TIE server.
The ePO schema queries about client and threat events enriched by TIE server information.
In Trellix ePO - On-prem, select Queries & Reports → New Query.
In the drop-down list for Database Type, select a schema:
TieServerSchema — On the Result Type tab, select which results are displayed, then click Next.
Option definitionsOption
Definition
Certificates
Certificate Enterprise Reputation — Shows the Enterprise reputation of the certificates.
Certificate Reputation — Retrieves summarized non-Enterprise reputation for certificates from the TIE server.
Certificates — Retrieves certificate information from the TIE server.
New Certificates on Systems — Retrieves information about systems with new certificates.
TIE Data Storage Management
Cleanup Trending Summary — Retrieves TIE server cleanup trending summary.
Files
File Enterprise Reputation — Retrieves summarized Enterprise Reputation from files.
File Reputation — Retrieves summarized non-Enterprise reputation for files from the TIE server.
Files — Retrieves file information from the TIE server.
New Files on Systems — Retrieves information about systems with new files.
ePO — Select Events and follow the prompts.
On the Chart tab, customize how the results are displayed, then click Next.
On the Columns tab, customize the columns for displaying the results, then click Next.
On the Filter tab, narrow the results of your query using the drop-down list, then click Run.
You obtain a customized chart with the threat intelligence information from your TIE server.