Audits That Cannot Be Imported

Prev Next

The following audit modules cannot be imported into a data acquisition script using the Web UI because they involve processing that can affect your system performance badly or because they perform a function that has nothing to do with data acquisition. When attempts are made to import scripts that include these audits, errors occur.

For some of these audits, Trellix provides preconfigured scripts that can be run for an individual host from the Hosts page in the Endpoint Security (HX) Web UI. If a preconfigured script is provided, it is listed below. All of these audits, however, can be requested using API bulk acquisitions. For additional information, see the Endpoint Security (HX) REST API Guide.

Audit Module

Supplied Preconfigured

Script (if any)

Legacy Name

agentinfo

---

---

config

---

---

configuration

---

---

containment

---

---

diagnostic

---

---

disk‑acquisition

Raw Disk

w32disk‑acquisition

dissolve

---

---

driver‑memoryacquire

Driver Memory

w32driver‑memoryacquire

file‑acquisition‑api

---

w32apifile‑acquisition

file‑acquisition‑raw

---

w32rawfile‑acquisition

intel-key

---

---

iocload

---

---

iocmatch

---

---

log-audit

---

---

memory‑acquisition

Full Memory

w32memory‑acquisition

multifile‑acquisition‑api

---

w32multifileapi‑acquisition

multifile‑acquisition‑raw

---

w32multifileraw‑acquisition

plist-acquisition

---

---

processes‑memoryacquire

Process Memory

w32processes‑memoryacquire

reprovision

---

---

restart

---

---

upgrade

---

---

For more information about the preconfigured scripts, see the Endpoint Security Server User Guide.