Make your event data available outside of the SIEM solution.
Follow the below steps to configure the event forwarding.
From the Trellix ESM dashboard, click
and select More Settings.On the system navigation tree, select Trellix ESM and click
.Click Event Forwarding and click Add.
Type a Name.
Select Source (Events/Logs).
Select data Format (CEF/SEF).
Select the time zone for the header of the syslog event.
Note
The below steps 8, 9, and 10 are optional.
Enable and/or setup obfuscation settings.
Select one or more filters to specify what events to forward.
Enable and/or setup a system profile to use for forwarder destination settings. Selecting an Event Forwarding system profile will automatically fill in most destination server settings.
Type the IP address to the destination server.
Choose between the UDP or TCP transport protocols.
Note
TCP protocol will automatically be selected when either SSH or TLS modes is selected.
Note
If a TCP event forwarder cannot connect to its destination for 24 hours, the forwarder will be disabled, and an internal Event will be logged to the TESM (Disabled Event Forwarding Destination - Unable to connect).
Select Facility.
Select Severity.
Select the security mode. Syslog is an unencrypted protocol, using SSH or TLS prevents other parties from examining event forwarding messages.
If SSH is selected,
Type the SSH port on which the destination SSH server is listening.
Type the SSH user name used to establish the SSH connection.
Copy the Event Forwarding SSH ECDSA Key to the authorized_keys file or equivalent on the destination SSH server.
Click Ok.