Data routing enables you to make your raw log data (events and flows) accessible to 3rd-party products without using the Trellix ESM or ELS.
From the Trellix ESM dashboard, click
and select More Settings.If Trellix Enterprise Security Manager - Event Receiver is not configured with an ELS:
On the system navigation tree, select the device and click
.Receiver Properties page opens.
Select Data Routing.
Select Enable Data Routing and click Yes.
On the Trellix Enterprise Security Manager - Event Receiver Properties page, select Data Sources.
Select Data Routing for the data sources you want to send public, raw data to the Data Streaming Bus.
Configure Message Forwarding rules to include the above data sources, see Configure Message Forwarding.