The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Queries, reports, and Common

Prev Next

Use queries to retrieve detailed information about the status of your managed systems and any threats in your environment. You can export, download, or combine queries into reports, and use queries as dashboard monitors.

Queries are questions that you ask Trellix ePO - On-prem, which returns answers as charts and tables. Reports enable you to package one or more queries into a single PDF document, for access outside of Trellix ePO - On-prem.

Similar information is available by accessing activity logs from the Trellix Endpoint Security (ENS) Client on individual systems.

You can view query data only for resources where you have permissions. For example, if your permissions grant access to a specific System Tree location, your queries return data only for that location.

Default queries

The module adds default queries to Trellix Groups. Depending on your permissions, you can use them as is, modify them, or create custom queries from events and properties in the Trellix ePO - On-prem database.

  • Endpoint Security: Client Interface Logon Audit Log

  • Endpoint Security: Currently Enabled Technology

  • Endpoint Security: Duration before Detection on Endpoints in the Last 2 Weeks

  • Endpoint Security: Installation Status Report

  • Endpoint Security: Locked Client Systems Due to Failed Password Attempts

  • Endpoint Security Platform: Hotfixes installed

  • Endpoint Security: Policy Compliance by Computer Name

  • Endpoint Security: Policy Compliance by Policy Name

  • Endpoint Security: Primary Vectors of Attack in the last 7 Days

  • Endpoint Security: Self Protection Compliance Status

  • Endpoint Security: Summary of Threats Detected in the last 7 Days

  • Endpoint Security: Threats Detected in the last 24 Hours

  • Endpoint Security: Threats Detected in the last 7 Days

  • Endpoint Security: Top 10 Attacking Systems in the Last 7 Days

  • Endpoint Security: Top Infected Users in the last 7 Days

  • Endpoint Security: Top Threats in the Last 48 Hours

Custom queries (Trellix ePO - On-prem)

The module adds default properties to the Endpoint Security feature group. You can use these properties to create custom queries.

Feature Group

Result Type

Property (Column)

Property (Column)

Endpoint Security

Endpoint Security Platform Systems

Access Protection Debug Logging Enabled

License Status

Access Protection Events Filter Level

Trellix GTI Proxy Type

Trellix Endpoint Security (ENS) Adaptive Threat Protection Debug Logging Enabled

On Access Scan Debug Logging Enabled

Trellix Endpoint Security (ENS) Adaptive Threat Protection Events Filter Level

On Access Scan Events Filter Level

Client Activity Logging Enabled

On Demand Scan Debug Logging Enabled

Client Activity Log Size in MB

On Demand Scan Events Filter Level

Client Debug Log Size in MB

Self Protection Additional Reasons

Client Log Files Location

Self Protection Compliance Status

Client User Interface Access Level

Self Protection Enabled

ESP Hotfix

Self Protection Reason

ESP Patch Version

Send Events to McAfee ePO Enabled

Exploit Prevention Debug Logging Enabled

SystemCore Version

Exploit Prevention Events Filter Level

Time-Based Password Enabled

Firewall Debug Logging Enabled

User Interface Password Changed

Firewall Events Filter Level

Web Control Debug Logging Enabled

Global Exclusions Status

Web Control Events Filter Level

Language

Windows Application Logging Enabled

Endpoint Security Platform Properties

Language (Endpoint Security Platform)

Product Version (Endpoint Security Platform)

Events

Endpoint Security Threat Events

Access Requested

Source Parent Process Signer

AMCore Content Version

Source Port

Analyzer Content Creation Date

Source Process Hash

Analyzer Content Version

Source Process Signed

Analyzer Trellix GTI Query

Source Process Signer

Analyzer Reg Info

Source Share Name

Analyzer Rule ID

Source Signed

Analyzer Rule Name

Source Signer

Analyzer Technology Version

Source URL Rating Code

API Name

Source URL Web Category

Attack Vector Type

Target Access Time

Cleanable

Target Create Time

Description

Target Description

Direction

Target Device Display Name

Duration Before Detection (Days)

Target Device PID

First Action Status

Target Device Serial Number

First Attempted Action

Target Device VID

Location

Target File Size (Bytes)

Module Name

Target Hash

Second Action Status

Target Modify Time

Second Attempted action

Target Name

Source Access Time

Target Parent Process Hash

Source Create Time

Target Parent Process Name

Source Description

Target Parent Process Signed

Source Device Display Name

Target Parent Process Signer

Source Device PID

Target Path

Source Device Serial Number

Target Share Name

Source Device VID

Target Signed

Source File Hash

Target Signer

Source File Path

Target URL

Source File Size (Bytes)

Task Name

Source Modify Time

Threat Detected On Creation

Source Parent Process Hash

Threat Impact

Source Parent Process Name

Topic

Source Parent Process Signed

For information about queries and reports, see the Trellix ePO - On-prem documentation.