Trellix Events API
Retrieve threat events and security incidents detected across managed endpoints. Events have a 3-day retention period.
Retrieve threat events and security incidents detected across managed endpoints. Events have a 3-day retention period.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/trellix-events-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Trellix ePO SaaS Events API
description: The Trellix ePO SaaS API provides cloud-based access to ePolicy Orchestrator management capabilities. It enables programmatic control of devices, events, tags, queries, and response actions through the Trellix cloud management platform. Authentication uses OAuth 2.0 client credentials with scoped permissions for each resource type.
version: '2.0'
contact:
name: Trellix Support
url: https://www.trellix.com/support/
termsOfService: https://www.trellix.com/en-us/about/legal/terms-of-use.html
servers:
- url: https://api.manage.trellix.com
description: Trellix Cloud Management Platform
security:
- bearerAuth: []
tags:
- name: Events
description: Retrieve threat events and security incidents detected across managed endpoints. Events have a 3-day retention period.
paths:
/epo/v2/events:
get:
operationId: listEvents
summary: List threat events
description: Retrieve threat events detected across managed endpoints. Events include malware detections, policy violations, and other security incidents. The data retention period for events is 3 days.
tags:
- Events
parameters:
- $ref: '#/components/parameters/limit'
- $ref: '#/components/parameters/offset'
- name: since
in: query
description: Return events that occurred after this ISO 8601 timestamp. Maximum lookback is 3 days due to data retention limits.
schema:
type: string
format: date-time
- name: filter
in: query
description: Filter expression to narrow events by attributes such as severity, analyzer name, or agent GUID.
schema:
type: string
responses:
'200':
description: Paginated list of threat events
content:
application/json:
schema:
type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/Event'
meta:
$ref: '#/components/schemas/PaginationMeta'
'401':
description: Unauthorized - invalid or expired access token
'403':
description: Forbidden - insufficient scope permissions
components:
schemas:
PaginationMeta:
type: object
properties:
totalItems:
type: integer
description: Total number of items matching the query
limit:
type: integer
description: Number of items per page
offset:
type: integer
description: Number of items skipped
Event:
type: object
properties:
id:
type: string
description: Unique identifier for the event
type:
type: string
description: Resource type identifier
attributes:
type: object
properties:
timestamp:
type: string
format: date-time
description: Time the event occurred
agentGuid:
type: string
format: uuid
description: GUID of the agent that reported the event
analyzerName:
type: string
description: Name of the security analyzer that detected the event
analyzerVersion:
type: string
description: Version of the detecting analyzer
threatName:
type: string
description: Name or identifier of the detected threat
threatSeverity:
type: string
description: Severity level of the threat
threatCategory:
type: string
description: Category classification of the threat
targetFileName:
type: string
description: File name targeted by the threat
targetFilePath:
type: string
description: Full file path of the targeted file
detectionMethod:
type: string
description: Method used to detect the threat
parameters:
limit:
name: limit
in: query
description: Maximum number of items to return per page
schema:
type: integer
default: 25
minimum: 1
maximum: 100
offset:
name: offset
in: query
description: Number of items to skip for pagination
schema:
type: integer
default: 0
minimum: 0
securitySchemes:
bearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
description: OAuth 2.0 access token obtained through the client credentials flow. Requires appropriate scope permissions such as epo.device.r, epo.device.w, epo.tags.r, epo.tags.w, epo.evt.r, epo.qery.g, epo.qery.u, epo.resp.ra, and epo.resp.ru.
externalDocs:
description: Trellix ePO SaaS Product Guide
url: https://docs.trellix.com/bundle/epolicy-orchestrator-saas-product-guide