To set up HTTP servers, perform the following subtasks:
Add the HTTP servers
Configure the HTTP server listing
On the Web UI, select the Settings tab.
Select Notifications on the side bar.
Click the HTTP tab to display the View and Add HTTP Servers area.
Click Add HTTP Server.
Enter the name of the HTTP server that will post the notification in the Server Name box and click Add New HTTP Server.
Note
Do not enter URLs and email addresses in the Server Name box.

Select the Enabled checkbox to choose which servers will post HTTP notifications. Select the Enable All checkbox to ensure that all listed servers post HTTP notifications.
Enter the URL of the server to post the HTTP notification in the Server URL box.
To apply the HTTP server listing changes, click Add New HTTP Server.
On the Web UI, select the Settings tab.
Select Notifications on the side bar.
Click the HTTPtab to display the View and Add HTTP Servers area.
Clcik the
icon of the server you want to edit.(Optional) If authentication is required for the server, select the Auth checkbox, enter the user name for HTTP authentication in the Username box, and enter the password for HTTP authentication in the Password box.
Select Malware Object or All Events in the Notification drop-down list box to post HTTP notifications when malware objects are detected.
Select the delivery frequency in the Delivery drop-down list box:
Note
Trellix recommends using Per Event notifications.
Default—Use the delivery frequency specified in the Default delivery box in the HTTP Settings area.
Per Event—Send a notification each time a malware object is detected.
Daily Digest—Send a daily notification of all malware objects detected the past 24 hours in the selected format and level of details (default is Concise).
(Optional) If you want to use SSL for notifications, select the SSL Enable checkbox and the SSL Verify checkbox.
Select a service provider in the Default provider drop-down list box. The default service provider is Generic.
Note
Trellix recommends using the generic service provider.
Select XML, JSON, or Text as the notification format and select which level of detail is provided in the Message Format drop-down list box. Select Default to use the format specified in the Default format box in the HTTP Settings area.
Normal—This format contains detailed information and abstracts, such as alert type, ID, source IP, malware name, hostname, and alert URL without redundant information
Concise—This format contains basic information, such as alert type, ID, source IP, malware name, hostname, and alert URL.
Extended—This format contains detailed information and abstracts, including data-theft information (if any) and static-analysis details. This format provides all details about files and objects modified during analysis.
To apply the HTTP server listing changes, click Update.