Use queries to retrieve detailed information about the status of your managed systems and any threats in your environment. You can export, download, or combine queries into reports, and use queries as dashboard monitors.
Queries are questions that you ask ePO - On-prem, which returns answers as charts and tables. Reports enable you to package one or more queries into a single PDF document, for access outside of ePO - On-prem.
Similar information is available by accessing activity logs from the Trellix Endpoint Security (ENS) Client on individual systems.
You can view query data only for resources where you have permissions. For example, if your permissions grant access to a specific System Tree location, your queries return data only for that location.
Tip
Best practice: For information on how to create a report of which computers have an Extra.DAT file installed, see KB59410.
Default queries
The module adds default queries to Trellix Groups. Depending on your permissions, you can use them as is, modify them, or create custom queries from events and properties in the ePO - On-prem database.
Endpoint Security Adaptive Threat Protection: Allow Events by Event Type
Endpoint Security Adaptive Threat Protection: Allow Events by Rule (Top 10)
Endpoint Security Adaptive Threat Protection: Allow Events for Last 30 Days
Endpoint Security Adaptive Threat Protection: Block Events by Event Type
Endpoint Security Adaptive Threat Protection: Block Events by Rule (Top 10)
Endpoint Security Adaptive Threat Protection: Block Events for Last 30 Days
Endpoint Security Adaptive Threat Protection: Clean Events by Event Type
Endpoint Security Adaptive Threat Protection: Clean Events by Rule (Top 10)
Endpoint Security Adaptive Threat Protection: Clean Events for Last 30 Days
Endpoint Security Adaptive Threat Protection: Content Status
Endpoint Security Adaptive Threat Protection: Enhanced Script Scanning Support by System
Endpoint Security Adaptive Threat Protection: Events by File (Top 10)
Endpoint Security Adaptive Threat Protection: Events by System (Top 10)
Endpoint Security Adaptive Threat Protection: Extra.DAT Signatures
Endpoint Security Adaptive Threat Protection: Observation Allow Events by Event Type
Endpoint Security Adaptive Threat Protection: Observation Allow Events by Rule (Top 10)
Endpoint Security Adaptive Threat Protection: Observation Allow Events for Last 30 Days
Endpoint Security Adaptive Threat Protection: Observation Block Events by Event Type
Endpoint Security Adaptive Threat Protection: Observation Block Events by Rule (Top 10)
Endpoint Security Adaptive Threat Protection: Observation Block Events for Last 30 Days
Endpoint Security Adaptive Threat Protection: Observation Clean Events by Event Type
Endpoint Security Adaptive Threat Protection: Observation Clean Events by Rule (Top 10)
Endpoint Security Adaptive Threat Protection: Observation Clean Events for Last 30 Days
Endpoint Security Adaptive Threat Protection: Observation Events by File (Top 10)
Endpoint Security Adaptive Threat Protection: Observation Events by System (Top 10)
Endpoint Security Adaptive Threat Protection: ML Protect Detection Events for Last 30 Days
Endpoint Security Adaptive Threat Protection: ML Protect Detection Events for Last 7 Days
Endpoint Security Adaptive Threat Protection: ML Protect Detection Events for Last Quarter
Endpoint Security Adaptive Threat Protection: ML Protect Detection Events in Last 24 Hours
Custom queries (ePO - On-prem)
The module adds default properties to the Endpoint Security feature group. You can use these properties to create custom queries.
Feature Group | Result Type | Property (Column) | Property (Column) |
|---|---|---|---|
Endpoint Security | Endpoint Security Adaptive Threat Protection Systems | Adaptive Threat Protection content version | Enable offline scanning |
ATP Hotfix | Enhanced script scanning supported by system | ||
ATP Patch Version | Enhanced script scanning supported by system reason | ||
Connection status | Is Supported OS | ||
Contained Applications | License Status | ||
Enable Adaptive Threat Protection | Monitor and remediate deleted and changed files | ||
Enable Adaptive Threat Protection Observe mode | ML Protect content date | ||
Enable client-based scanning | ML Protect content version | ||
Enable cloud-based scanning | ML Protect engine date | ||
Enable enhanced remediation | ML Protect engine version | ||
Enable enhanced script scanning (includes AMSI integration) | Reputation Source | ||
Enable enhanced script scanning Observe mode | Signatures in Extra.DAT | ||
Credential Theft Protection Version | Enable Credential Theft Protection Scanning | ||
Enable Credential Theft Protection Observe Mode | |||
Endpoint Security Platform Systems | Adaptive Threat Protection Debug Logging Enabled | Adaptive Threat Protection Events Filter Level | |
Adaptive Threat Protection Events | Balance Security For | File MD5 Hash | |
Certificate Company Creator | File Reputation | ||
Certificate Hash | File SHA1 Hash | ||
Certificate Name | Object Type | ||
Certificate Public Key Hash | ML Protect Scanning Sensitivity Level | ||
Content Version | Rule ID | ||
Detection Type | User Prompt Comments | ||
File Company Creator | |||
Others | Story Graph Properties → Adaptive Threat Protection Rules | Description | Rule Name |
Long Description |
For information about queries and reports, see the ePO - On-prem documentation.