Use Active Response to search for current endpoint data.
Add a ePO - On-prem device with Active Response to Trellix ESM.
In ePO - On-prem, make sure that Send Restrictions and Receive Restrictions are set to All Systems or have a tag that is also tagged on the receiver ( → → ).
Define search settings for the ePO - On-prem device.
From the Trellix ESM dashboard, click
and select System properties.On the system navigation tree, select the device, then click
.Click Trellix ePO Properties, then click Connection.
Select Enable DXL and specify an Agent Wake-up Port (default is 8081).
On the Trellix ESM dashboard, select a view with a table widget, such as Event Analysis.
Click an event, then click
.Select → , then select a predefined search type.
Note
Search types are grayed out if the table doesn't have the appropriate fields for the search.
File details of the source and destination IP address, such as the operating system and name
User details
Source IP address process details for what established the connection
Destination IP address process details for what established the connection
Anyone connected to the same source or destination IP address