You can configure Trellix Agent to forward events to ePO - On-prem on a priority basis, if they are equal to or greater than a specified severity.
During normal operation, Trellix Agent and security software on the managed system generate software events regularly. These events are uploaded to the server at each agent-server communication, at a set upload interval and are stored in the database. These events can range from information about regular operation, such as when Trellix Agent enforces policies locally, to critical events, such as when a virus is detected and not cleaned. A typical deployment of Trellix Agent in a large network can generate thousands of these events an hour.
If you plan to use Automatic Responses, enable priority uploading of higher severity events for those features to function as intended. Trellix Agent sends lower priority events to ePO - On-prem on later agent-server communication intervals.
Specific event severities are determined by the product that generates the events. You can enable priority uploading of events on the Events tab of the Trellix Agent policy pages.
The table lists the events generated by Trellix Agent with IDs and severity.
Event ID | Description | Severity |
|---|---|---|
2401 | Common update success | 3 |
2402 | Common update fail | 4 |
2411 | Deployment success | 3 |
2412 | Deployment fail | 4 |
2413 | Trellix Agent uninstall attempt | 3 |
2422 | Policy enforce fail | 3 |
2427 | Props collect fail | 3 |