Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.
Queries are questions that you ask ePO - On-prem, which returns answers as charts and tables. Reports enable you to package one or more queries into a single PDF document, for access outside of ePO - On-prem.
Similar information is available by accessing activity logs from the Trellix Endpoint Security (ENS) Client on individual systems.
You can view query data only for resources where you have permissions. For example, if your permissions grant access to a specific System Tree location, your queries return data only for that location.
Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.
The module adds default queries to Trellix Groups. Depending on your permissions, you can use them as is, modify them, or create custom queries from events and properties in the ePO - On-prem database.
Endpoint Security Firewall: Firewall Client Rules By Process
Endpoint Security Firewall: Firewall Client Rules By Process/Port Range
Endpoint Security Firewall: Firewall Client Rules By Process/User
Endpoint Security Firewall: Firewall Client Rules By Protocol/System Name
Endpoint Security Firewall: Compliance Status
Endpoint Security Firewall: Count of Firewall Client Rules
Endpoint Security Firewall: Errors
Endpoint Security Firewall: Events from Trellix GTI in the last 6 months
Endpoint Security Firewall: Events in the last 24 hours
Endpoint Security Firewall: Hotfixes Installed
Endpoint Security Firewall: Intrusion events in the last 24 hours
Endpoint Security Firewall: Status
Endpoint Security Firewall: Traffic block events in the last 24 hours
Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.
The module adds default properties to the Endpoint Security feature group. You can use these properties to create custom queries.
Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed. | Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed. | Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed. | Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed. |
|---|---|---|---|
Endpoint Security | Endpoint Security Firewall Systems | Additional Compliance Status Reason | Firewall Patch Version |
Compliance Status Reason | Firewall Rules Policy | ||
Endpoint Security Firewall client version | Firewall Service Running | ||
Endpoint Security Firewall Compliance Status | Firewall Status | ||
Firewall Adaptive Mode Status | Firewall Trusted Applications Policy | ||
Firewall Fault | Firewall Trusted Networks Policy | ||
Firewall Hotfixes | Install Directory (32 bit version) | ||
Firewall Last Policy Enforcement | Install Directory (64 bit version) | ||
Firewall License Status | Language | ||
Firewall Mode | Product Version | ||
Firewall Name Client UI Policy | Reboot Required | ||
Firewall Options Policy | |||
Endpoint Security Firewall Properties | Language (Endpoint Security Firewall) | Product Version (Endpoint Security Firewall) | |
Endpoint Security Platform Systems | Firewall Debug Logging Enabled | Firewall Event Filter Level |
For information about queries and reports, see the ePO - On-prem documentation.