The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure VA sources

Prev Next

To communicate with vulnerability assessment (VA) sources, add them to the system, add communication parameters for the VA vendor, schedule parameters for how often data is retrieved, and change severity calculations.

  1. On the system navigation tree, select a Trellix Enterprise Security Manager - Event Receiver, then click the Properties icon Settings.png.

  2. Click Vulnerability Assessment.

    • Type the Frontline client ID number. Digital Defense Frontline requires Client ID.

    • On FusionVM, the name of the company that must be scanned. If you leave company name blank, the system scans all companies to which the user belongs. Separate multiple company names with commas.

    • (Qualys QualysGuard) Select the method to retrieve the VA data. HTTP/HTTPS is the default. Options include: SCP, FTP, NFS, CIFS, and Manual upload.

      Note

      A Qualys QualysGuard log file manual upload has a file size limit of 2 GB.

    • Type the domain of the Windows system (optional, unless your domain controller or server exists in a domain).

    • Identify the directory where exported scan files reside.

    • Identify the exported scan file format (XML, NBE).

    • Identify the location where Saint was installed on the server. The installation directory for a Saint appliance scanner is

       /usr/local/sm/
    • Identify IP addresses:

      • eEye REM — IP address of the eEye server that sends trap information

      • eEye Retina — IP address of the client holding exported scan files (.rtd)

      • Nessus, OpenVAS, LanGuard, and Rapid7 Metasploit Pro — IP address of the client holding exported scan files

      • NGS — IP address of the system storing the Squirrel reports

      • Rapid7, Lumension, nCircle, and Saint — IP address of the respective server

    • Identify the method used to retrieve exported scan files (SCP, FTP, NFS, or CIFS mount). LanGuard always uses CIFS.

    • If you select nfs in the Method field, the system adds Mount Directory fields. Enter the mount directory set when you configured nfs.

    • Identify passwords:

      • Nessus, OpenVAS, LanGuard, and Rapid7 Metasploit Pro — The password of SCP or FTP.

      • NGS — The password for the SCP and FTP methods.

      • Qualys and FusionVM — The password for the Qualys Front Office or FusionVM user name.

      • Rapid7 Nexpose, Lumension, nCircle, and Saint — The password to use when connecting to the web server.

      • Digital Defense Frontline — The web interface password.

    • Identify the port Rapid7 Nexpose, Lumension, nCircle, or Saint web server are listening on. The default for Rapid7 Nexpose is 3780, for Lumension is 205, for nCircle is 443, and for Saint is 22.

    • Identify the name of a particular project or workspace, or leave it blank to grab all projects or work spaces.

    • Identify the proxy IP address, user name, password for the proxy user name, and the port on which the HTTP proxy is listening.

    • Type the URL of the Qualys or FusionVM server to query.

    • Identify the remote path and share name for CIFS method Nessus, OpenVAS, eEye Retina, Metasploit Pro, LanGuard, and NGS.

      You can use back or forward slashes in the path name (for example,

      Program Files\CIFS\va

      or

      /Program Files/CIFS/va)
    • Indicate the frequency to retrieve VA data from the Trellix Enterprise Security Manager - Event Receiver:

      • Daily — Select the time you want the data retrieved each day.

      • Weekly — Select the day of the week and the time on that day you want the data retrieved.

      • Monthly — Select the day of the month and the time on that day that you want the data retrieved.

      If you do not want the data retrieved at a preset time, select Disabled.

      Note

      eEye REM does not support data retrieval from the source so the data must be retrieved from the Trellix Enterprise Security Manager - Event Receiver.

    • Indicate the frequency to retrieve VA data from the VA source.

    • Saint — Identify the session data is gathered from. To include all sessions, type All.

    • If you select authNoPriv or authPriv in the SNMP security level field, SNMP authentication password is active. Enter the password for the authentication protocol selected in the SNMP authentication protocol field.

    • If you select authNoPriv or authPriv in the SNMP security level field, SNMP authentication protocol is active. Select the type of protocol for this source: MD5 or SHA1 (SHA1 and SHA see the same protocol type). Make sure that your REM Events Server configuration matches your selection.

    • Select the SNMP community that was set when you configured the REM Events Server.

    • If you select authPriv in the SNMP security level field, SNMP privacy password SNMP Community are active. Enter the password for the DES or AES privacy protocol. In FIPS mode, AES is the only option available.

    • If you select authPriv in the SNMP security level field, SNMP privacy protocol is active and you can select either DES or AES. In FIPS mode, AES is the only option available.

    • Select the security level for this source:

      • noAuthNoPriv — No authentication protocol and no privacy protocol

      • authNoPriv — Authentication protocol but no privacy protocol

      • authPriv — Both authentication and privacy protocol.

      Note

      SNMP authentication and privacy fields become active based on the security level you select. Make sure that your REM Events Server configuration matches your selection.

    • Select the security name in REM Events Server Configuration.

    • Select the version of SNMP for the source. The SNMP fields are activated based on the version you select.

    • (Optional) The SNMPv3 Engine ID of the trap sender, if you use an SNMPv3 profile.

    • (Optional) Type the password that is required to access the Saint installation directory.

    • Indicate the default time-out value for a source or provide a specific time-out value. You can increase the time-out value to allow more VA data retrieval time. If you provide a value, it is used for all communications.

    • (Optional) Authentication token that can be set in the Metasploit Global Settings.

    • URL to the Digital Defense Frontline server.

    • If you select to use the HTTP proxy, the Proxy IP Address, Proxy Port, Proxy Username, and Proxy Password fields become active.

    • If you select ftp in the Method field, this field becomes active. Then select when to use passive mode.

    • Select Use sudo if you have access to the Saint installation directory and want to use this access.

    • Select whether to use a previously defined profile. Use System Profile (eEye REM) deactivates all SNMP fields. When you select one of the existing system profiles, the system populates fields with the information in the selected profile.

    • If you use Windows authentication mode for the SQL Server, enter the user name of the Windows box. If not, enter the user name of the SQL Server.

      • Nessus, OpenVAS, and Rapid7 Metasploit Pro — User name of SCP or FTP

      • NGS — User name for the SCP and FTP methods

      • Qualys or FusionVM — Front Office or FusionVM user name with which to authenticate

      • Rapid7 Nexpose, Lumension, nCircle, and Saint — User name when connecting to the web server

      • Digital Defense Frontline — Web interface user name

    • Identify the VA source name.

    • Identify the wildcard expression used to describe the name of exported scan files. The wildcard expression can use an asterisk (*) or question mark (?) with the standard definition of wildcard in a file name.

      Note

      If you have both NBE and XML files, specify if you want NBE or XML files in this field (for example, *.NBE or *.XML). If you only use an asterisk (*), you get an error.

  3. Write any changes to the device.

  4. Click Apply or OK.