Data sources represent the assets connected to your network. An asset is any device with an IP address. Receivers collect event logs from data sources and then parse the logs and send them to storage. Add data sources and define their settings so they collect the data you need.
Make sure that the Trellix Enterprise Security Manager - Event Receiver for this data source is listed on the system navigation tree.
Make sure that the data source is configured to send logs to a Receiver. See the Data Source Configuration Reference.
If you have issues while configuring a data source, run the Data Source Health Check → and see the Troubleshooting section of the Data Source Configuration Reference.
From the Trellix ESM dashboard, click and select More Settings .
On the Receiver Properties page, click Data Sources.
9E5mPA table lists existing data sources (including child and client data sources) and identifies how the data source processes data.
Note
If SNMP Trap is selected, the data source accepts standard SNMP traps from any manageable network device with the capability of sending SNMP traps. When Trellix ESM receives these traps, it generates an event for the data source. To send or receive SNMP traps via IPv6, formulate the IPv6 address as an IPv4 conversion address.
Do one of the following:
To add a new data source, click Add.
To add a child data source to an existing data source, click Add Child.
To edit an existing data source, select the data source then click Edit.
Configure the data source.
To pre-populate SNMP and syslog protocol-based devices, click Use System Profiles
Enter a Data Source Vendor and Data Source Model. These determine what information you enter for the data source. Advanced syslog parser (ASP) data sources that generate data without UTF-8 encoding, select Generic as the vendor and Advanced Syslog Parser as the model.
Select a Data Format to set the parsing method.
Select a Data Retrieval method.
For SCP, set the LANG environment variable to lang=C.
SCP File Source does not support relative paths. Define the full location.
For CIFS File Source or NFS File Source, select a collection method.
Enable the method the Trellix Enterprise Security Manager - Event Receiver uses to process data.
Complete additional fields based on vendor, device model, data retrieval method, or protocol of the device.
The data sources appear under the Trellix Enterprise Security Manager - Event Receiver on the navigation tree.