The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Dashboards, monitors, and Threat Prevention

Prev Next

Keep watch on the status of your managed systems and any threats in your environment using your customizable dashboard.

Dashboards are collections of monitors that track activity in your ePO - On-prem environment.

Default dashboards and monitors

Threat Prevention contributes monitors to several Common dashboards.

Common dashboards and Threat Prevention monitors

Dashboard

Monitor

Description

Endpoint Security: Compliance Status

Whether the enabled state in the policy matches the enabled state on the client system. If the technology is enabled in policy and disabled on the client, the system is noncompliant.

Endpoint Security Threat Prevention: Access Protection Compliance Status

Number of systems with Access Protection compliant or noncompliant:

  • Compliant — Enabled state in policy matches the enabled state on client system

  • Non-Compliant — Enabled state in policy doesn't match the enabled state on client system

Endpoint Security Threat Prevention: AMCore Content Compliance Status

Number of systems with AMCore content compliant or noncompliant:

  • Compliant — The AMCore content creation date is less than 7 days old.

  • Non-Compliant — The AMCore content creation date is more than 7 days old.

Endpoint Security Threat Prevention: Exploit Prevention Compliance Status

Number of systems with Exploit Prevention compliant or noncompliant:

  • Compliant — Enabled state in policy matches the enabled state on client system

  • Non-Compliant — Enabled state in policy doesn't match the enabled state on client system

Endpoint Security Threat Prevention: On-Access Scan Compliance Status

Number of systems with on-access scanner protection compliant or noncompliant:

  • Compliant — Enabled state in policy matches the enabled state on client system

  • Non-Compliant — Enabled state in policy doesn't match the enabled state on client system

Endpoint Security: Content Status

Versions of the content files and engine.

Endpoint Security Threat Prevention: Content Status

Version of the AMCore Content and the number of systems with that version installed.

Endpoint Security Threat Prevention: Exploit Prevention Content Status

Version of the Exploit Prevention Content and the number of systems with that version installed.

Endpoint Security: Installation Status

Whether a module is installed.

Endpoint Security Threat Prevention: Hotfixes Installed

Number of systems with Threat Prevention hotfixes installed, including hotfix version numbers.

Endpoint Security: Scan Duration

Average time for system scans.

Endpoint Security Threat Prevention: Duration of Completed Full Scans in the Last 7 Days

Number of completed Full Scan system scans by time in hours (from less than 1 hour to greater than 12 hours) and the number of systems per duration.

For each duration, this monitor shows:

  • Scan start and end time

  • System name

  • Last communicated time

Endpoint Security Threat Prevention: Duration of Completed Quick Scans in the Last 7 Days

Number of completed Quick Scan system scans by time in hours (from less than 10 minutes to greater than an hour) and the number of systems per duration.

For each duration, this monitor shows:

  • Scan start and end time

  • System name

  • Last communicated time

Endpoint Security: Threat Event Origins

How threats are entering the environment.

Endpoint Security Threat Prevention: Applications with the Most Exploits in the Last 7 Days

Applications with the most buffer overflow exploits, including the number of detections.

Endpoint Security: Protection Summary (Only in ePO - SaaS)

Displays information on the number of nodes installed, protected, and whether the content is up to date (i.e., less than a week old).

Protection Status

There is also an option to start the Install Protection workflow from this monitor.

In this monitor, the criteria for Installed, Protected, and Up-to-date count is as follows:

  • Installed: The customer must have all licensed Endpoint modules installed on all end-nodes to get a perfect score.

  • Protected: The customer must have all licensed Endpoint module technologies enabled on all end-nodes to get a perfect score.

  • Up-to-date: The customer must have AMCore content that is less than a week old installed on all end-nodes to get a perfect score.



Custom dashboards (ePO - On-prem)

Depending on your permissions, you can create custom dashboards and add monitors using default Trellix ENS queries.

For information about dashboards, see the ePO - On-prem documentation.