The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Dashboards, monitors, and Host Intrusion Prevention

Prev Next

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Dashboards are collections of monitors that track activity in your ePO - On-prem environment.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

The module provides default dashboards and monitors. Depending on your permissions, you can use them as is, modify them to add or remove monitors, or create custom dashboards using ePO - On-prem.

Host Intrusion Prevention includes the following default dashboard.

Host Intrusion Prevention dashboards and monitors

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Endpoint Security: Firewall Dashboard

Status of Trellix Endpoint Security (ENS) Firewall.

Endpoint Security Firewall: Events in the last 24 hours

Number of intrusion or detection events from Host Intrusion Prevention in the last 24 hours.



In addition to the default Host Intrusion Prevention dashboard, Host Intrusion Prevention contributes monitors to several Common dashboards.

Common dashboards and Host Intrusion Prevention monitors

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Endpoint Security: Compliance Status

Whether a technology is enabled (protection status).

Endpoint Security Firewall: Compliance Status

Number of systems with Host Intrusion Prevention protection enabled or disabled.

Endpoint Security: Installation Status

Whether a module is installed.

Endpoint Security Firewall: Hotfixes Installed

Number of systems with Host Intrusion Prevention hotfixes installed, including hotfix version numbers.



Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Depending on your permissions, you can create custom dashboards and add monitors using default Trellix ENS queries.

For information about dashboards, see the ePO - On-prem documentation.