The following audit modules cannot be imported into a data acquisition script using the Endpoint Security (HX) Web UI because they involve processing that can badly affect your system performance or because they perform a function that has nothing to do with data acquisition. When attempts are made to import scripts that include these audits, errors occur.
For some of these audits, Trellix provides preconfigured data acquisition scripts that can be run for an individual host from the HostsHosts page. Associated preconfigured data acquisition scripts are listed in the table below. All of these audits can be requested using API bulk acquisitions. For additional information, see the Endpoint Security (HX) REST API Guide.
Audit module | Supplied preconfigured script (if any) | Legacy name |
|---|---|---|
agentinfo | --- | --- |
config | --- | --- |
configuration | --- | --- |
containment | --- | --- |
diagnostic | --- | --- |
disk‑acquisition | w32disk‑acquisition | |
dissolve | --- | --- |
driver‑memoryacquire | w32driver‑memoryacquire | |
file‑acquisition‑api | --- | w32apifile‑acquisition |
file‑acquisition‑raw | --- | w32rawfile‑acquisition |
intel-key | --- | --- |
iocload | --- | --- |
iocmatch | --- | --- |
log-audit | --- | --- |
memory‑acquisition | Full Memory | w32memory‑acquisition |
multifile‑acquisition‑api | --- | w32multifileapi‑acquisition |
multifile‑acquisition‑raw | --- | w32multifileraw‑acquisition |
plist-acquisition | --- | --- |
processes‑memoryacquire | w32processes‑memoryacquire | |
reprovision | --- | --- |
restart | --- | --- |
upgrade | --- | --- |
For more information about audit modules, see the Endpoint Security (HX) Audit Reference Guide.