The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Queries, reports, and Adaptive Threat Protection

Prev Next

Use queries to retrieve detailed information about the status of your managed systems and any threats in your environment. You can export, download, or combine queries into reports, and use queries as dashboard monitors.

Queries are questions that you ask Trellix ePO - On-prem, which returns answers as charts and tables. Reports enable you to package one or more queries into a single PDF document, for access outside of Trellix ePO - On-prem.

Similar information is available by accessing activity logs from the Trellix Endpoint Security (ENS) Client on individual systems.

You can view query data only for resources where you have permissions. For example, if your permissions grant access to a specific System Tree location, your queries return data only for that location.

Tip

Best practice: For information on how to create a report of which computers have an Extra.DAT file installed, see KB59410.

Default queries

The module adds default queries to Trellix Groups. Depending on your permissions, you can use them as is, modify them, or create custom queries from events and properties in the Trellix ePO - On-prem database.

  • Endpoint Security Adaptive Threat Protection: Allow Events by Event Type

  • Endpoint Security Adaptive Threat Protection: Allow Events by Rule (Top 10)

  • Endpoint Security Adaptive Threat Protection: Allow Events for Last 30 Days

  • Endpoint Security Adaptive Threat Protection: Block Events by Event Type

  • Endpoint Security Adaptive Threat Protection: Block Events by Rule (Top 10)

  • Endpoint Security Adaptive Threat Protection: Block Events for Last 30 Days

  • Endpoint Security Adaptive Threat Protection: Clean Events by Event Type

  • Endpoint Security Adaptive Threat Protection: Clean Events by Rule (Top 10)

  • Endpoint Security Adaptive Threat Protection: Clean Events for Last 30 Days

  • Endpoint Security Adaptive Threat Protection: Content Status

  • Endpoint Security Adaptive Threat Protection: Enhanced Script Scanning Support by System

  • Endpoint Security Adaptive Threat Protection: Events by File (Top 10)

  • Endpoint Security Adaptive Threat Protection: Events by System (Top 10)

  • Endpoint Security Adaptive Threat Protection: Extra.DAT Signatures

  • Endpoint Security Adaptive Threat Protection: Observation Allow Events by Event Type

  • Endpoint Security Adaptive Threat Protection: Observation Allow Events by Rule (Top 10)

  • Endpoint Security Adaptive Threat Protection: Observation Allow Events for Last 30 Days

  • Endpoint Security Adaptive Threat Protection: Observation Block Events by Event Type

  • Endpoint Security Adaptive Threat Protection: Observation Block Events by Rule (Top 10)

  • Endpoint Security Adaptive Threat Protection: Observation Block Events for Last 30 Days

  • Endpoint Security Adaptive Threat Protection: Observation Clean Events by Event Type

  • Endpoint Security Adaptive Threat Protection: Observation Clean Events by Rule (Top 10)

  • Endpoint Security Adaptive Threat Protection: Observation Clean Events for Last 30 Days

  • Endpoint Security Adaptive Threat Protection: Observation Events by File (Top 10)

  • Endpoint Security Adaptive Threat Protection: Observation Events by System (Top 10)

  • Endpoint Security Adaptive Threat Protection: ML Protect Detection Events for Last 30 Days

  • Endpoint Security Adaptive Threat Protection: ML Protect Detection Events for Last 7 Days

  • Endpoint Security Adaptive Threat Protection: ML Protect Detection Events for Last Quarter

  • Endpoint Security Adaptive Threat Protection: ML Protect Detection Events in Last 24 Hours

Custom queries (Trellix ePO - On-prem)

The module adds default properties to the Endpoint Security feature group. You can use these properties to create custom queries.

Feature Group

Result Type

Property (Column)

Property (Column)

Endpoint Security

Endpoint Security Adaptive Threat Protection Systems

Adaptive Threat Protection content version

Enable offline scanning

ATP Hotfix

Enhanced script scanning supported by system

ATP Patch Version

Enhanced script scanning supported by system reason

Connection status

Is Supported OS

Contained Applications

License Status

Enable Adaptive Threat Protection

Monitor and remediate deleted and changed files

Enable Adaptive Threat Protection Observe mode

ML Protect content date

Enable client-based scanning

ML Protect content version

Enable cloud-based scanning

ML Protect engine date

Enable enhanced remediation

ML Protect engine version

Enable enhanced script scanning (includes AMSI integration)

Reputation Source

Enable enhanced script scanning Observe mode

Signatures in Extra.DAT

Credential Theft Protection Version

Enable Credential Theft Protection Scanning

Enable Credential Theft Protection Observe Mode

Endpoint Security Platform Systems

Adaptive Threat Protection Debug Logging Enabled

Adaptive Threat Protection Events Filter Level

Adaptive Threat Protection Events

Balance Security For

File MD5 Hash

Certificate Company Creator

File Reputation

Certificate Hash

File SHA1 Hash

Certificate Name

Object Type

Certificate Public Key Hash

ML Protect Scanning Sensitivity Level

Content Version

Rule ID

Detection Type

User Prompt Comments

File Company Creator

Others

Story Graph PropertiesAdaptive Threat Protection Rules

Description

Rule Name

Long Description

For information about queries and reports, see the Trellix ePO - On-prem documentation.