Devices and Events

Prev Next

View a comprehensive list of devices impacted by campaigns and threats. The list includes devices which are currently vulnerable to attack, or are not correctly configured based on your security posture score.

This page is accessible by clicking a device or detection count found in several locations in the user interface. These locations include:

  • Security Posture Score— Device count against each element.

  • Campaign Detections — Total detection count.

  • Devices — Exposed devices and insufficient coverage devices count.

  • Campaigns table — Exposed devices, insufficient coverage, resolved, and unresolved detections.

  • Threats table — All impacted devices and total detections.

Clicking a device displays all events detected on that device.

Item

Description

Filters

Select to filter devices based on the following criteria:

  • Filter by days to create a date range

  • Detected Campaigns

  • Detected Threats

  • Resolution status

  • Insufficient coverage

  • Security posture score elements

Devices

For each device you can view the following details:

  • System Name

  • IP Address

  • Tags — Add an ePolicy Orchestrator - On-premises tag from the Take action drop down menu and choose an existing or new tag to apply.

    Note

    NSP and non-managed devices will be ignored.

  • User(s)

  • Operating System — Windows and Linux.

  • Last Communicated — View the amount of time since the last communication in hours or days.

  • Observation(s) — View a summary of the events. For example, Unresolved detections(s)

Click a row or System Name to view events on the device and its policy details. The Actions button in the drawer also provides an option to view the device in the System Tree.

Event and policy details

View all events and policy details for a particular device.

Item

Description

Filter

Search or select an option to view a subset of the events.

  • Search — Enter MD5 or SHA256 search terms.

  • View — Select All, Resolved, or Unresolved.

Event Details

View a list of events with the following information:

File Name

  • Date and time

Click an event to expand the view:

Event Details

  • Campaign or Threat related to the event.

  • Status — Resolved or unresolved

Basic Properties

  • MD5

  • SHA256

  • File Path

  • File Name

  • PE Product Name (for campaign events only)

  • PE Product Version (for campaign events only)

Detection Details

  • Product Name (detected by)

  • Product Version (detected by)

  • AMCore Content Version

  • Operating System (Windows and Linux)

  • Resolution (For threat events only)

  • Detection (For threat events only)

Mark this event as resolved - Trellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the timestamp, and additional comments.

Mark all as resolved - Trellix Insights allows you to resolve multiple events for a device.

  1. Select the device.

  2. On the device details page, under the Events tab, select ViewUnresolved. The list of unresolved events are displayed.

  3. Click Mark all as resolved.

  4. Select the events from the list and click Mark as Resolved.

Process Trace - Process tracing displays details for processes executed on your endpoints in graph format. If a trace is available for an event, a graph icon is enabled. See Process Trace for more information.

Policy Details

This tab groups violations by ePO policy. For example, all violations in the Zero-Day category map to the ePO Endpoint Security Adaptive Threat Protection policy.

View a list of events with the following information:

File Name

  • Date and time

Click an event to expand the view:

Event Details

  • Campaign or Threat related to the event.

  • Status — Resolved or unresolved

Basic Properties

  • MD5

  • SHA256

  • File Path

  • File Name

  • PE Product Name (for campaign events only)

  • PE Product Version (for campaign events only)

Detection Details

  • Product Name (detected by)

  • Product Version (detected by)

  • AMCore Content Version

  • Resolution (For threat events only)

  • Detection (For threat events only)

Mark this event as resolved - Trellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the timestamp, and additional comments.

Process Trace - Process tracing displays details for processes executed on your endpoints in graph format. If a trace is available for an event, a graph icon is enabled. See Process Trace for more information.