The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure third-party data consumers

Prev Next

Use raw Trellix ESM data in third-party applications.

Configure an event forwarding rule on Trellix ESM with an external certificate and a target topic.

Download the root certificate and the certificate configured for the forwarding rule.

  1. On the computer that hosts the data consumer, add an entry to the host file: <DSB_IP> <DSB_GUID>. Where DSP_IP is the IP address of the VM that hosts the Trellix Data Streaming Bus and DSB_GUID is the value from /etc/NitroGuard/devSettings.conf on the same VM.

  2. Configure the third-party application.

    1. Set the topic to the target topic created when you configured the event forwarding rule.

    2. Specify the port on the Trellix Data Streaming Bus VM that allows external access (default is 9092).

    3. Enter the IP address of the VM that hosts the Trellix Data Streaming Bus.

    4. Specify the root certificate and the certificate configured for the forwarding rule.