You can connect the Trellix Security Orchestrator to Trellix ESM to automate the security processes and enable effective threat response.
Make sure the SOAR Management privilege is enabled from System Properties.
Make sure to generate API keys from the user profile section of Trellix Security Orchestrator.
Important
The integration of Trellix ESM with Trellix Security Orchestrator requires a licensed version of Trellix Security Orchestrator.
From the Trellix ESM dashboard, click
and select More Settings.On the system navigation tree, select Trellix ESM and click
.From System Properties, click SOAR Integration.
Select SOAR Endpoints and click Add.
In the SOAR Type option, select Trellix Security Orchestrator..
In the Name option, enter a name for Trellix Security Orchestrator.
In the Hostname option, enter the IP address of Trellix Security Orchestrator.
In the API Keys option, enter the API keys and click OK.
To verify SOAR integration with Trellix ESM:
Click Test.
When the test confirmation screen appears, click Yes.
Make sure the SOAR test result is successful.
Note
If the test result is not successful, verify the hostname and API keys.