The following audit modules cannot be imported into a data acquisition script using the Endpoint Security (HX) Web UI because they involve processing that can badly affect your system performance or because they perform a function that has nothing to do with data acquisition. When attempts are made to import scripts that include these audits, errors occur.
For some of these audits, Trellix provides preconfigured data acquisition scripts that can be run for an individual host from the Hosts page. Associated preconfigured data acquisition scripts are listed in the table below. All of these audits can be requested using API bulk acquisitions.
Audit module | Supplied preconfigured script (if any) | Legacy name |
|---|---|---|
config | --- | --- |
configuration | --- | --- |
containment | --- | --- |
diagnostic | --- | --- |
disk‑acquisition | w32disk‑acquisition | |
dissolve | --- | --- |
driver‑memoryacquire | w32driver‑memoryacquire | |
file‑acquisition‑api | --- | w32apifile‑acquisition |
file‑acquisition‑raw | --- | w32rawfile‑acquisition |
intel-key | --- | --- |
iocload | --- | --- |
iocmatch | --- | --- |
log-audit | --- | --- |
memory‑acquisition | Full Memory | w32memory‑acquisition |
multifile‑acquisition‑api | --- | w32multifileapi‑acquisition |
multifile‑acquisition‑raw | --- | w32multifileraw‑acquisition |
plist-acquisition | --- | --- |
processes‑memoryacquire | w32processes‑memoryacquire | |
reprovision | --- | --- |
restart | --- | --- |
upgrade | --- | --- |
For more information about audit modules, see the
Endpoint Security (HX) Audit Reference Guide
.