You can create URLs to integrate other products with Trellix EDR. You can use these URLs to create investigations automatically on Trellix EDR.
Log on to Trellix EDR as administrator.
Click the configuration icon on the top-right corner to access the Configuration page.
Click Manage integrations, then click + Add to add an integration.
In the Name field, type the required name, then from the Action drop-down list, select Add Evidence.
From the Delivery method drop-down list, select Use Trellix ePO extension as proxy or Direct to Cloud, then click Save.
Note
Use Trellix ePO extension as proxy if your SIEM does not have direct connection to the internet. You also need to select the Enable/Disable Service option next to Forward API on Trellix EDR server settings on ePO - On-prem.
A Webhook URL is created https://api.soc.trellix.com/wh/v1/webhook/<webhook id>
You can regenerate the Webhook URL by clicking Regenerate and copy the Webhook URL by clicking Copy.
You can delete an existing integration by clicking the Remove integration icon.