The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

How host names work

Prev Next

Associate device host names with their corresponding IP addresses. Add, edit, remove, look up, update, and import host names, and set the time when an auto-learned host name expires.

When you view event data, you can show the host names associated with the IP addresses in the event by clicking the Show host names icon GUID-03BFBCA8-5E7F-45E1-B2E8-C466EDBD149D-low.png at the bottom of view components.

If existing events are not tagged with a host name, the system searches the host table on Trellix ESM and tags the IP addresses with their host names. If the IP addresses don't appear on the host table, the system performs a Domain Name System (DNS) lookup to locate the host names. The search results then show up in the view and are added to the host table.

On the host table, this data is selected as Auto Learned and expires after the time designated in the Entries expire after field located below the host table on System PropertiesHosts. If the data has expired, another DNS lookup is performed the next time you select Show host names on a view.

The host table lists auto-learned and added host names and their IP addresses. You can add information to the host table manually by entering an IP address and host name individually or by importing a tab-delimited list of IP addresses and host names. The more data you enter in this manner, the less time is spent on DNS lookups. If you enter a host name manually, it doesn't expire, but you can edit or remove it.