The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Agent Telemetry using Sysinfo

Prev Next

The agent reports additional telemetry around operational aspects of the module within Sysinfo. This information is viewed using the Host Management module on the Endpoint Security Server or queried through the Host Information API available on the Endpoint Security Server. The table describes the aspects reported by the module.

Telemetry Field

Description

augmentationErrors

Number of hits for which metadata collection for the event could not be completed, accumulated since the module was installed

helixConnectionStatus

The status of the agent’s connection to Helix

helixID

The ID of Helix instance that the hits is forwarded to

helixLastConnectionAttemptTimestamp

The timestamp of the last attempt to connect to Helix

helixTrendMessagesDelivered

Number of hits delivered to Helix since helixTrendWindowStartTimestamp

helixTrendMessagesSkipped

Number of hits skipped while attempting to deliver to Helix since helixTrendWindowStartTimestamp

helixTrendWindowStartTimestamp

Interval start time for the two preceding fields

hitCount

Number of all hits encountered since the agent was installed

intelActiveURI

URI of the current streaming rule content

intelActiveVersion 1

Version ID of the current streaming rule content

intelLastUpdated 1

Timestamp of the last update for the current streaming rule content

intelLastUpdateValid

'1' if the last update of the streaming rule content was valid

intelIndicatorMetaNotes 2

In the case that intelIndicatorMetasPresent is not ‘1’, additional information around the failure mode

intelIndicatorMetasPresent 2

If the streaming module has received the additional streaming rule content metadata

intervalByteCount 1

Total number of bytes sent to Helix within the current streaming telemetry interval

intervalByteLimit

Currently configured data limit threshold

intervalExceeded 1

‘1’ if the intervalByteCount exceeds the intervalByteLimit

intervalTimeElapsed

Time elapsed since the current streaming telemetry interval started, in seconds

lastHitTimestamp

Timestamp of the last hit detected (ISO-8601 format)

moduleUptime

Time since the last restart of the streaming module on the agent, in seconds

operational 1

‘1’ if the streaming module has successfully initialized and is awaiting hit notification

operationalNotes

In the case that operational is not ‘1’, additional information around the failure mode

timeSinceLastHit

Time since the last hit was detected in seconds

tokenManagerConnectionStatus

Status of the connection to the Helix token manager

tokenManagerLastConnectionAttempt Timestamp

Timestamp of the last attempt to connect to the Helix token manager

version1

Version ID of the agent Streaming module

1These fields are available as columns within the Host Management Module.