Forward a backup of the raw data to your storage device for long-term storage.
Trellix ESM supports the following types of storage:
Server Message Block/Common Internet File System (SMB/CIFS)
Network File System (NFS)
Syslog Forwarding
SMB/CIFS and NFS store, in the form of data files, a backup of all raw data sent to the receiver by data sources.
Syslog Forwarding sends raw data for syslog events as a continuous stream of combined syslogs to the device. It supports only UDP packets.
The receiver can forward to only one type of storage at a time; you can configure all three types, but only one type can be enabled to archive data
Note
This feature doesn't support NetFlow, sflow, or IPFIX data source types.
To set up receiver data archiving, see Trellix Enterprise Security Manager Installation Guide.