Use this file to discover all available pages before exploring further.
The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.
Enabling the server module does not automatically enable it for agents. You must perform the following steps to enable the feature on the agent.
To enable IOC Streaming on a host set, move the Enable IOC Streaming on the host toggle to ON, and save the policy changes. The IOC Streaming module will be enabled the next time the configuration is updated on the agent.
Important
If the IOC Streaming module is not displayed on your web UI, you can add the using the Categories button.
To enable IOC Streaming on a host set, complete the following steps:
Log in to the Endpoint Security Web UI as an administrator.
From the Admin tab, select Policies.
On the Policies page, click the appropriate policy.
Select IOC Streaming in the Configurations list.
In the IOC Streaming details panel, move the IOC Streaming toggle to On, and click Save.
The IOC Streaming module will be enabled the next time the configuration is updated on the agent.
Note
For the module to function on the agent, Real-Time Indicator Detection must be turned on. If you enable the module on an agent without this turned on, no activity events are detected.
Endpoint Security Modules (HX) > IOC Streaming > Endpoint Security IOC Streaming Module User Guide Release 1.3.167 > Configuring the IOC Streaming module
Endpoint Security Modules (HX) > IOC Streaming > Endpoint Security IOC Streaming Module User Guide Release 1.3.169 > Configuring the IOC Streaming module