Limit the event data forwarded to a syslog server on Trellix ESM.
Verify you have permission to access devices in the filter.
From the Trellix ESM dashboard, click
and select More Settings.On the system navigation tree, select Trellix ESM and click
.Click Event Forwarding.
Click Add, then click Event Filters.
Fill in the filter fields:
Note
Comma separated lists should not have space characters.
Device:
Click
and select one or more device.
Destination or Source IP:
Enter a single IP, comma separated list, or CIDR range of IP addresses (192.168.0.0/16).
Destination Port:
Enter a single port or comma separated list.
Protocol:
Enter a Single protocol or comma separated list.
Values can be protocol ID or String.
Device Type:
Click
and select one or more device type.
Normalized ID:
Click
select one or more Norm ID.
Severity:
Select Greater than or equal to.
Enter a severity number between 0 and 100.