The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Level 7 collection on Trellix Intrusion Prevention System Manager

Prev Next

Layer 7 data populates the Trellix Intrusion Prevention System Manager database after the NSM event is written to its database. It doesn't come into the system as part of the event.

To pull Layer 7 information from the NSM, you can delay when the event is pulled so that Layer 7 data is included. This delay applies to all NSM events, not only the ones with associated Layer 7 data.

You can set this delay when performing three different actions related to the NSM:

  • Adding a Trellix NSM device to the console

  • Configuring an NSM device

  • Adding an NSM data source

Adding a Trellix Intrusion Prevention System Manager device

When adding the Trellix Intrusion Prevention System Manager device to Trellix ESM, select Enable Layer 7 Collection and set the delay on the Add Device Wizard.

Configuring a Trellix Intrusion Prevention System Manager device

After adding a Trellix Intrusion Prevention System Manager device to Trellix ESM, configure the connection settings for the device. You can select Enable Layer 7 Collection and set the delay.

Adding a Trellix Intrusion Prevention System Manager data source

To add a Trellix Intrusion Prevention System Manager data source to a Receiver, select Trellix in Data Source Vendor and Network Security Manager - SQL Pull (ASP) in Data Source Model. You can select Enable Layer 7 Collection and set the delay.