Use queries to retrieve detailed information about the status of your managed systems and any threats in your environment. You can export, download, or combine queries into reports, and use queries as dashboard monitors.
Queries are questions that you ask Trellix ePO - On-prem, which returns answers as charts and tables. Reports enable you to package one or more queries into a single PDF document, for access outside of Trellix ePO - On-prem.
Similar information is available by accessing activity logs from the Trellix Endpoint Security (ENS) Client on individual systems.
You can view query data only for resources where you have permissions. For example, if your permissions grant access to a specific System Tree location, your queries return data only for that location.
Default queries
The module adds default queries to Trellix Groups. Depending on your permissions, you can use them as is, modify them, or create custom queries from events and properties in the Trellix ePO - On-prem database.
Endpoint Security: Client Interface Logon Audit Log
Endpoint Security: Currently Enabled Technology
Endpoint Security: Duration before Detection on Endpoints in the Last 2 Weeks
Endpoint Security: Installation Status Report
Endpoint Security: Locked Client Systems Due to Failed Password Attempts
Endpoint Security Platform: Hotfixes installed
Endpoint Security: Policy Compliance by Computer Name
Endpoint Security: Policy Compliance by Policy Name
Endpoint Security: Primary Vectors of Attack in the last 7 Days
Endpoint Security: Self Protection Compliance Status
Endpoint Security: Summary of Threats Detected in the last 7 Days
Endpoint Security: Threats Detected in the last 24 Hours
Endpoint Security: Threats Detected in the last 7 Days
Endpoint Security: Top 10 Attacking Systems in the Last 7 Days
Endpoint Security: Top Infected Users in the last 7 Days
Endpoint Security: Top Threats in the Last 48 Hours
Custom queries (Trellix ePO - On-prem)
The module adds default properties to the Endpoint Security feature group. You can use these properties to create custom queries.
Feature Group | Result Type | Property (Column) | Property (Column) |
|---|---|---|---|
Endpoint Security | Endpoint Security Platform Systems | Access Protection Debug Logging Enabled | License Status |
Access Protection Events Filter Level | Trellix GTI Proxy Type | ||
Trellix Endpoint Security (ENS) Adaptive Threat Protection Debug Logging Enabled | On Access Scan Debug Logging Enabled | ||
Trellix Endpoint Security (ENS) Adaptive Threat Protection Events Filter Level | On Access Scan Events Filter Level | ||
Client Activity Logging Enabled | On Demand Scan Debug Logging Enabled | ||
Client Activity Log Size in MB | On Demand Scan Events Filter Level | ||
Client Debug Log Size in MB | Self Protection Additional Reasons | ||
Client Log Files Location | Self Protection Compliance Status | ||
Client User Interface Access Level | Self Protection Enabled | ||
ESP Hotfix | Self Protection Reason | ||
ESP Patch Version | Send Events to McAfee ePO Enabled | ||
Exploit Prevention Debug Logging Enabled | SystemCore Version | ||
Exploit Prevention Events Filter Level | Time-Based Password Enabled | ||
Firewall Debug Logging Enabled | User Interface Password Changed | ||
Firewall Events Filter Level | Web Control Debug Logging Enabled | ||
Global Exclusions Status | Web Control Events Filter Level | ||
Language | Windows Application Logging Enabled | ||
Endpoint Security Platform Properties | Language (Endpoint Security Platform) | Product Version (Endpoint Security Platform) | |
Events | Endpoint Security Threat Events | Access Requested | Source Parent Process Signer |
AMCore Content Version | Source Port | ||
Analyzer Content Creation Date | Source Process Hash | ||
Analyzer Content Version | Source Process Signed | ||
Analyzer Trellix GTI Query | Source Process Signer | ||
Analyzer Reg Info | Source Share Name | ||
Analyzer Rule ID | Source Signed | ||
Analyzer Rule Name | Source Signer | ||
Analyzer Technology Version | Source URL Rating Code | ||
API Name | Source URL Web Category | ||
Attack Vector Type | Target Access Time | ||
Cleanable | Target Create Time | ||
Description | Target Description | ||
Direction | Target Device Display Name | ||
Duration Before Detection (Days) | Target Device PID | ||
First Action Status | Target Device Serial Number | ||
First Attempted Action | Target Device VID | ||
Location | Target File Size (Bytes) | ||
Module Name | Target Hash | ||
Second Action Status | Target Modify Time | ||
Second Attempted action | Target Name | ||
Source Access Time | Target Parent Process Hash | ||
Source Create Time | Target Parent Process Name | ||
Source Description | Target Parent Process Signed | ||
Source Device Display Name | Target Parent Process Signer | ||
Source Device PID | Target Path | ||
Source Device Serial Number | Target Share Name | ||
Source Device VID | Target Signed | ||
Source File Hash | Target Signer | ||
Source File Path | Target URL | ||
Source File Size (Bytes) | Task Name | ||
Source Modify Time | Threat Detected On Creation | ||
Source Parent Process Hash | Threat Impact | ||
Source Parent Process Name | Topic | ||
Source Parent Process Signed |
For information about queries and reports, see the Trellix ePO - On-prem documentation.