The following audit modules cannot be imported into a data acquisition script using the Web UI because they involve processing that can affect your system performance badly or because they perform a function that has nothing to do with data acquisition. When attempts are made to import scripts that include these audits, errors occur.
For some of these audits, Trellix provides preconfigured scripts that can be run for an individual host from the Hosts page in the Endpoint Security (HX) Web UI. If a preconfigured script is provided, it is listed below. All of these audits, however, can be requested using API bulk acquisitions. For additional information, see the Endpoint Security (HX) REST API Guide.
Audit Module | Supplied Preconfigured Script (if any) | Legacy Name |
|---|---|---|
agentinfo | --- | --- |
config | --- | --- |
configuration | --- | --- |
containment | --- | --- |
diagnostic | --- | --- |
disk‑acquisition | Raw Disk | w32disk‑acquisition |
dissolve | --- | --- |
driver‑memoryacquire | Driver Memory | w32driver‑memoryacquire |
file‑acquisition‑api | --- | w32apifile‑acquisition |
file‑acquisition‑raw | --- | w32rawfile‑acquisition |
intel-key | --- | --- |
iocload | --- | --- |
iocmatch | --- | --- |
log-audit | --- | --- |
memory‑acquisition | Full Memory | w32memory‑acquisition |
multifile‑acquisition‑api | --- | w32multifileapi‑acquisition |
multifile‑acquisition‑raw | --- | w32multifileraw‑acquisition |
plist-acquisition | --- | --- |
processes‑memoryacquire | Process Memory | w32processes‑memoryacquire |
reprovision | --- | --- |
restart | --- | --- |
upgrade | --- | --- |
For more information about the preconfigured scripts, see the Endpoint Security Server User Guide.