The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Queries, reports, and Host Intrusion Prevention

Prev Next

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Queries are questions that you ask ePO - On-prem, which returns answers as charts and tables. Reports enable you to package one or more queries into a single PDF document, for access outside of ePO - On-prem.

Similar information is available by accessing activity logs from the Trellix Endpoint Security (ENS) Client on individual systems.

You can view query data only for resources where you have permissions. For example, if your permissions grant access to a specific System Tree location, your queries return data only for that location.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

The module adds default queries to Trellix Groups. Depending on your permissions, you can use them as is, modify them, or create custom queries from events and properties in the ePO - On-prem database.

  • Endpoint Security Firewall: Firewall Client Rules By Process

  • Endpoint Security Firewall: Firewall Client Rules By Process/Port Range

  • Endpoint Security Firewall: Firewall Client Rules By Process/User

  • Endpoint Security Firewall: Firewall Client Rules By Protocol/System Name

  • Endpoint Security Firewall: Compliance Status

  • Endpoint Security Firewall: Count of Firewall Client Rules

  • Endpoint Security Firewall: Errors

  • Endpoint Security Firewall: Events from Trellix GTI in the last 6 months

  • Endpoint Security Firewall: Events in the last 24 hours

  • Endpoint Security Firewall: Hotfixes Installed

  • Endpoint Security Firewall: Intrusion events in the last 24 hours

  • Endpoint Security Firewall: Status

  • Endpoint Security Firewall: Traffic block events in the last 24 hours

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

The module adds default properties to the Endpoint Security feature group. You can use these properties to create custom queries.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Endpoint Security

Endpoint Security Firewall Systems

Additional Compliance Status Reason

Firewall Patch Version

Compliance Status Reason

Firewall Rules Policy

Endpoint Security Firewall client version

Firewall Service Running

Endpoint Security Firewall Compliance Status

Firewall Status

Firewall Adaptive Mode Status

Firewall Trusted Applications Policy

Firewall Fault

Firewall Trusted Networks Policy

Firewall Hotfixes

Install Directory (32 bit version)

Firewall Last Policy Enforcement

Install Directory (64 bit version)

Firewall License Status

Language

Firewall Mode

Product Version

Firewall Name Client UI Policy

Reboot Required

Firewall Options Policy

Endpoint Security Firewall Properties

Language (Endpoint Security Firewall)

Product Version (Endpoint Security Firewall)

Endpoint Security Platform Systems

Firewall Debug Logging Enabled

Firewall Event Filter Level

For information about queries and reports, see the ePO - On-prem documentation.