You can determine which events are forwarded to the server using server settings and event filtering.
Note
These settings affect the bandwidth used in your environment, and the results of event-based queries.
For details about product features, usage, and best practices, click ? or Help.
Select Menu → Configuration → Server Settings, select Event Filtering, then click Edit at the bottom of the page.
Select the events you want forwarded, either all or individual events.
To forward all available events, select All events to the server.
Note
Select All and Deselect All are disabled when you select All events to the server.
To forward only the events you specified, select Only selected events to the server.
Select where you want the selected events stored.
Click Store selected in Trellix ePO — Store all selected events in the ePO - On-prem database.
Click Forward selected to syslog — Forward all selected events to syslog.
Click Store selected in both — Store all selected events in both the ePO - On-prem and forward to syslog. This is the default setting.
Note
If a product extension provides an event storage option for an event type during registration, that event storage option is saved. If a product extension does not provide an event storage option for an event type during registration, the default is to store in both.
Select event source.
Events from any source—Any source includes the Trellix Agent, ePO - On-prem, and more.
Events that were generated by the sending agent—Only events generated by the Trellix Agent.
Click Save.
Changes to these settings take effect after all agents have communicated with the ePO - On-prem server.