The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure IVX for analysis

Prev Next

Configure the files that need to be uploaded to IVX for execution and analysis.

Verify that sandboxing is enabled and configured correctly in ePO - On-prem on the Policy Catalog page through health checks.

Important

Before integrating IVX with Trellix TIE, the user needs to ensure that a cluster is configured on IVX and the node role is set to broker, even if there is only a single IVX server that requires integration. For more information about configuring an IVX cluster, see IVX Administration Guide.

If you select multiple files, the Portable Executable (PE) files are prioritized and sent to IVX sandboxing.

Task
  1. In ePO - On-prem, select Policy CatalogThreat Intelligence Exchange.

  2. Click TIE Settings, then click Edit on My Default Policy Settings.

  3. Select Sandboxing. In IVX, enable the service and configure the server list (credentials, IP address) and the connection settings.

  4. Click (+) to select multiple servers.

    Note

    By default, Enforce Certificate Validations is enabled to avoid MiTM attacks

  5. Filter the File Types to send to IVX.

  6. Click Save when you are finished.

TIE server submits the files selected to IVX for further analysis.