The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Create a virtual Trellix SIEM device on an Azure VM

Prev Next

Deploy a Trellix SIEM device image on an Azure VM.

  • Run the installer script for the device you want to create.

  • Consult with your Trellix ESM specialist to determine the optimal size of your VM.

These instructions refer to third-party products. You might need to adapt to changes in interfaces or processes.

  1. From the Azure Resource group page, select the device image.

  2. Click Create VM.

  3. Select a Resource Group.

  4. Type a Virtual machine name.

  5. Configure the VM Size with sufficient cores and memory to support the device.

  6. Set the Authentication type to Password and set the logon credentials.

    Note

    These credentials are replaced by the Trellix default credentials when the VM is created. You don't need to remember these credentials.

  7. For an Trellix ESM device, set Public inbound ports to Allow selected ports. For other devices, set it to None.

  8. Under Select inbound ports, select HTTPS, HTTP, and SSH.

  9. Click Next: Disks.

  10. If you want to add a disk, click Create and attach a new disk. A Trellix Support specialist can tell you which devices support additional disks.

  11. Set the disk Size appropriate for your device, and click OK.

  12. Click the remaining tabs and configure the VM.

    Tip

    Tags help you keep track of your VMS. For example, you can add tags for owner, environment, or date created.

  13. On the Review + Create tab, review the information and click Create.

    The virtual server is created and a confirmation is shown. This can take a few minutes. It will be listed in the Virtual machines

  14. Select the new VM and copy the IP address.

  15. For an Trellix ESM, paste the IP address into a web browser and log on with theTrellix default credentials.

  16. For devices other than Trellix ESM, log on to the Trellix ESM and key the device.

    Note

    Disabling the DHCP setting on an Azure VM deployment is not supported. Request a static DHCP address, if a permanent IP address is needed.

(Optional) Disable or delete the temporary Linux VM you used to run the installation script.