Create and apply a policy that actively gathers hardware, software, and configuration details from your managed systems.
Create a Collect Data policy
Log on to your Trellix ePO - On-prem console.
Navigate to → .
For the Product, select → .
Click New Policy to open the new policy dialog box.
Select an existing policy to duplicate, give the new policy a name, and click OK. The policy configuration wizard is displayed.
Configure General system properties
In the policy wizard, navigate to the General tab.
Select the checkboxes for the system information you want to collect. The options are:
USB devices: Gathers details of USB device drivers on the node.
Installed Network cards: Collects Network Interface Card details.
MSI Version: Gathers the Microsoft Windows Installer version.
Installed Software: Collects a list of all installed software, including hidden software.
Internet Explorer version: Gathers the version and patch level of Internet Explorer.
Running processes at property collection: Gathers a list of processes running when the data is collected.
Environmental Variables (in SYSTEM context): Collects the values for TEMP, TMP, and SystemRoot.
Shares: Collects shared data from the endpoint.
Services installed: Gathers a list of all services and their status.
Path (in SYSTEM context): Collects the system's Path variable value.
NullSession shares and pipes: Gathers the list of defined NullSession Pipes and Shares.
Installed Hotfixes (relies on Registry only): Collects all installed Microsoft updates.
Click Save.
Configure custom data collection
Navigate to the Custom tab.
To collect a custom environment variable, enter its name in the "Get value of custom environment variable" field.
To collect a registry value, enter the full key path into the "Query Registry Values" field and click Add to list.
To enable detailed logging for troubleshooting, select the Enable logging checkbox. This creates a
SIRService.logfile on the endpoint.Note
This log file contains sensitive registry information and should only be enabled for troubleshooting purposes.
Configure file searches
Navigate to the Find File tab.
Select a folder from the drop-down list and type the file name you want to search for. You can use wildcards (For exmaple, *
.exe). This search will find the file and determine its version and SHA-256 hash (if available).Click Add to list.
Click Save.