Endpoint Security (HX) API

Prev Next

The Trellix Endpoint Security (HX) application programming interface (API) allows users to automate certain actions and integrate security information and event management (SIEM) solutions from Trellix and other companies. The API provides access to information about endpoints, acquisitions, alerts, source alerts, conditions, indicators, and containment. The Endpoint Security (HX) API uses role-based access control (RBAC) and representational state transfer (REST) architecture.

HX_EndpointSecurity_grapic.png

Using the Central Management System appliance

During normal operations, the Central Management System appliance receives alerts and other data from the networked File Protect, Email Security — Server, and Network Security appliances. This data is held in the Central Management System database and is used to produce reports and alerts that are then available to the system users. The Endpoint Security (HX) API can be used to access and update these reports and alerts through the Central Management System appliance. Users can also use the API to submit suspicious objects through the Central Management System appliance to the Malware Analysis appliance.

ALL_Alerts_fig.jpg