The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Enriched data

Prev Next

When viewing results in the grid view, it is important to understand which data was observed on the endpoint and which data was enriched by the endpoint. Enrichment happens when the endpoint module observes a logon event with an IP address or a hostname, but not both. In this situation, the module attempts to resolve the IP address or hostname. Data enriched in this way is categorized into two categories:

  • An IP address or hostname derived at the time when the logon event occurred (a, “real time logon”)

  • An IP address or hostname derived for a logon event that occurred in the past (a, “historical logon”). Historical logons are observed when Logon Tracker first runs on a system and processes existing event logs (“backfill”), or if Logon Tracker is disabled temporarily and then resumes.

Data resolved in real time is more likely to be accurate. However, in some cases resolution of historical logon activity can still add investigative value. For example, the hostname resolution for a print server with a static IP address should always resolve to the correct IP address, regardless of when the logon occurred.

In the grid view, any host name or IP address enriched in real time appears in italics. Any host name or IP address enriched for a historical logon (and therefore potentially less accurate) appears in italics with an asterisk. The figure shows how each type of enriched data is displayed. Hovering over the italicized text will provide a pop-up describing the type of enrichment that occurred.

HomeScreen3.png

The following sections provide more detail on the various search features and interface controls.