The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Enable data routing

Prev Next

Data routing enables you to make your raw log data (events and flows) accessible to 3rd-party products without using the Trellix ESM or ELS.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. If Trellix Enterprise Security Manager - Event Receiver is not configured with an ELS:

    1. On the system navigation tree, select the device and click Settings.png.

      Receiver Properties page opens.

    2. Select Data Routing.

    3. Select Enable Data Routing and click Yes.

  3. On the Trellix Enterprise Security Manager - Event Receiver Properties page, select Data Sources.

  4. Select Data Routing for the data sources you want to send public, raw data to the Data Streaming Bus.

  5. Configure Message Forwarding rules to include the above data sources, see Configure Message Forwarding.