Priority event forwarding

Prev Next

You can configure Trellix Agent to forward events to ePO - On-prem on a priority basis, if they are equal to or greater than a specified severity.

During normal operation,  Trellix Agent and security software on the managed system generate software events regularly. These events are uploaded to the server at each agent-server communication, at a set upload interval and are stored in the database. These events can range from information about regular operation, such as when  Trellix Agent enforces policies locally, to critical events, such as when a virus is detected and not cleaned. A typical deployment of Trellix Agent in a large network can generate thousands of these events an hour.

If you plan to use Automatic Responses, enable priority uploading of higher severity events for those features to function as intended. Trellix Agent sends lower priority events to ePO - On-prem on later agent-server communication intervals.

Specific event severities are determined by the product that generates the events. You can enable priority uploading of events on the Events tab of the Trellix Agent policy pages.

The table lists the events generated by Trellix Agent with IDs and severity.

Event ID

Description

Severity

2401

Common update success

3

2402

Common update fail

4

2411

Deployment success

3

2412

Deployment fail

4

2413

Trellix Agent uninstall attempt

3

2422

Policy enforce fail

3

2427

Props collect fail

3