Dashboard

Prev Next

When you first log in to the Endpoint Security (HX) Web UI, the Dashboard is displayed. You can also navigate to the Dashboard by selecting Dashboard from the main menu, or by clicking the Trellix logo at the top of the page.

The Dashboard displays key metrics and links to help you quickly access information about threat-related activity on your hosts.

Dashboard.png

The Dashboard includes a number of different sections. Numbers in blue can be selected. For more information about user roles and authentication, refer to the Endpoint Security (HX) System Administration Guide.

Prerequisites
  • Admin, Analyst, Senior Analyst, or Investigator privileges (full access)

  • Operator privilege (read only access)

Accessing the page

To access the Dashboard, click the Trellix logo at the top of the page.

Alerts

The Alerts section is the top section of the Dashboard and displays information about alerts triggered on your network.

DashAlerts.png

The Alerts section shows the information in the following table. Click any numbers in these fields to jump to the Hosts page, filtered by your selection.

Icon

Field

Description

---

Total hosts with alerts

The total number of hosts with alerts.

IconBlock.png

Exploit blocks on

The number of hosts on which exploits were prevented (blocked).

IconAlert.png

Alerts detected on

The number of high-value hosts with alerts.

IconExploit.png

Exploits on

The number of hosts on which exploits were detected. Note that the number of exploits that were prevented (blocked) are included in the exploit alert counts.

MALicon.png

Malware on

The number of hosts on which malware detection protection alerts were triggered.

The exploit (IconExploit.png and IconBlock.png) and malware (MALicon.png) alert count sections are shown on the Dashboard even when Exploit Guard or malware detection protection are turned off.

Recent file acquisitions

The Recent File Acquisitions section provides information about recent file acquisitions, including the number of acquisition requests in progress and the number of failed acquisition requests. Click any number in this section to jump to the Acquisitions page, filtered by your selection.

If a recent acquisition is shown, click Download to download the acquisition to your computer. You can also click View Details to view brief details about the acquisition.

Click View All to see all file acquisitions. Triage acquisitions are not included in this list. To see all acquisitions, including triage acquisitions, select Acquisitions from the Trellix main menu.

Contained hosts

The Contained Hosts section shows the number of contained hosts, including the number of requests for containment and the number of failed containment requests. Click the numbers in this section to jump to the Hosts page, filtered by your selection.

Active hosts

The Active Hosts section shows the number of hosts on the network over a customizable period. Using this section, you can detect an unexpected drop in connectivity between hosts and the Endpoint Security (HX).

Inactive hosts

The Inactive Hosts section shows the number of monitored hosts on your network that have not checked in for 30 days or more.

Mobile devices

The Mobile Devices section shows the number of mobile devices on your network and the number of devices that are out of compliance with your network policy.

Tip

The Mobile Device section is available only when the Mobile Threat Protection (MTP) Service is active on your network and linked to your Endpoint Security (HX) software. For more information about the MTP Service, contact your Trellix sales representative.