The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Define data collection settings

Prev Next

Define how Trellix ESM devices collect event, flow, and log data.

Verify that you have the following permissions:

  • Policy Administrator and Device Management or

  • Policy Administrator and Custom Rules

You can select to check for events, flows, and logs automatically or you can check for them manually. The rate at which you check for them depends on your system's level of activity and how often you want to receive status updates. You can also specify which devices check for each type of information and set inactivity threshold settings for devices managed by Trellix ESM.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select Trellix ESM and click Settings.png.

    • Trellix Application Data Monitor and Trellix Enterprise Security Manager - Event Receiver devices collect events, flows, and logs.

      Click Events, Flows & Logs.

    • Trellix ESM - ACE devices collect events and logs.

      Click Events & Logs.

    • Trellix Enterprise Security Manager - Enterprise Log Manager and Trellix Enterprise Log Search devices collect logs.

      Click Logs.

  3. Define the data collection settings (which vary by device):

    • If Trellix ESM automatically downloads rules from the rules server, select to roll out downloaded rules automatically to the device.

    • Select to check for events, flows, or logs automatically or check now by clicking Get.

    • Schedule a daily time when Trellix ESM pulls data from each device and when each device sends data to the Trellix Enterprise Security Manager - Enterprise Log Manager. Schedule a time that avoids using the network at peak times, leaving the bandwidth available for other applications.

      Caution

      Scheduling event, flow, and log data collection can result in data loss and delay data delivery.

    • Choose to add events that match vulnerability assessment source data, become a vulnerability event, and generate an alert on the local Trellix ESM. The Policy Editor properties are the same for each of these events and can't be changed (for example, severity is always 100).

    • See the last time the system retrieved the device's events or flows, whether the process was successful, and the number of events or flows retrieved.

    • See the date and time of the last event, string, or flow record retrieved. Changing this value allows you to set the date and time from which you want to retrieve events, strings, or flows. For example, if you enter November 13, 20xx at 10:30 a.m. in the Last Downloaded Event Record field, click Apply, then click Get Events, Trellix ESM retrieves events on this device from that time to date.

    • Define device inactivity thresholds so that the system notifies you when those devices don't receive events or flows for the specified period. If the threshold you set is reached, a yellow health status flag appears next to the device node on the system navigation tree.

    • Define whether to store the geolocation data for each device. Trellix ESM collects source and destination geolocation data to identify the physical locations of threats.

      Note

      Geolocation provides the geographic location of computers connected to the Internet.