Streaming policy

Prev Next

The Streaming policy controls the flow of endpoint activity data for threat analysis. It allows you to configure the Trace plug-in to send security event information to the Trellix EDR cloud or an external S3 bucket.

Trace

  • Trace Scanning — Configures the Trace plug-in on managed devices to analyze system activity and identify the root cause of security incidents. For all exclusions, use a semicolon (;) to separate items; the maximum character limit is 3072.

    Option

    Definition

    Enable Trace

    Enables the Trace plug-in on the endpoints. This is enabled by default.

    Log Level

    Sets the level of detail for Trace log files (Debug, Trace, Info, Warning, Error). Each level includes its own information and all levels below it. Use the lowest log level possible, or disable this feature if you do not need log information.

    • Debug — Detailed debug information.

    • Trace — Contains most variable value dumps. This can be too verbose to debug problems on production systems.

    • Info — Logs messages that highlight the progress of the Trace plug-in.

    • Warning — Information about potentially harmful situations.

    • Error — Error events that might prevent the Trace plug-in from running.

    The Trace log file is located at the following location:

    • Windows — C:\ProgramData\Trellix\XClient\exts\plugin\UnifiedEdr\data\trace.log

    • Linux — /opt/Trellix/XClient/bin/xclient -g /tmp/xclient.log

    • mac — /Library/Application\ Support/Trellix/xclient/exts/plugin/UnifiedEdr/data/trace.log

    Report internal reputation failures to Trellix ePO

    Reports a threat event to ePO - SaaS if the Trace plug-in has internal connection issues. This is disabled by default.

    Enable deep inspection of Windows API calls

    Activates the agent's code injection detection plug-in to monitor and inspect Windows API usage for threat detection. This is enabled by default.

    Enable ETW-TI inspection of Windows API calls

    Enables the use of Event Tracing for Windows - Threat Intelligence (ETW-TI) to inspect Windows API calls for advanced threat detection. This is enabled by default.

    Maximum size (MB) of the device storage that can be used by the Traces

    Sets the size limit for the Trace database on the device. When this limit is reached, the oldest records are discarded.

    Default: 80 MB

    Range: 0–8192 MB

    Interval to send trace events to Trellix EDR cloud

    Specifies how often, in seconds, to send trace event notifications to the EDR cloud.

    Default: 30 seconds

    Range: 30–1800 seconds

  • Trace Destination — Collects detailed endpoint activity data and sends it to the cloud for in-depth analysis and threat investigation.

    Note

    This feature is enabled only for Windows endpoints.

    Option

    Definition

    Send traces to Trellix EDR cloud

    Sends traces collected on the endpoint to the Trellix EDR cloud. This is enabled by default.

    Send traces to S3 bucket (Windows only)

    Sends traces collected on the Windows endpoint to a compatible external cloud storage S3 bucket, such as Amazon Web Services (AWS) or Google Cloud Platform (GCP). This is disabled by default.

    When enabled, add valid details in the fields displayed:

    • Access Key ID — Enter the access key ID for your S3 bucket..

    • S3 bucket Secret Access Key — Enter the secret access key associated with the Access Key ID.

    • S3 default Region Name — Enter the region where your S3 bucket is hosted (for example, us-east-1).

    • S3 bucket Name — Enter the exact name of your S3 bucket.

    • Interval (in seconds) to send trace events to S3 bucket — Specifies how often, in seconds, to send trace events.

      Default: 30 seconds

      Range: 10–1800 seconds

    • Specify (optional) S3 endpoint — Use this field to define a custom endpoint URL. This is required for certain S3-compatible services such as GCP Storage (for example, https://storage.googleapis.com). For standard AWS S3 buckets, this field can usually be left blank.

    • Verifying the Configuration — After you have entered your S3 bucket details, click the Verify configuration button to validate the settings. This check ensures that the EDR cloud can successfully connect to your bucket. You will receive one of the following messages:

      • Success: Indicates a valid connection. No issues were found with the bucket name, credentials, or permissions.

      • Warning: The connection is successful, but the provided credentials have excessive permissions. For this feature to function, the only required permission is the ability to create objects. This warning flags unnecessary permissions such as Get, List, or Delete. You can still save the configuration, but we recommend you limit the permissions to only what is required.

  • Exclusion — Configure exclusions to prevent the monitoring of trusted files, processes, or folders. This option is available when collectors are enabled and supports a character limit of 3072. Separate multiple items using a semicolon (;).

    Option

    Definition

    Exclude process(es) by full path on Windows

    Excludes specified processes from being traced.

    The supported paths are:

    • Full paths

    • FOLDERID_* paths

    • Paths with System environment variables. User environment variables are not supported.

    • Wildcards

      The path <Folder>\* includes all processes in <Folder> and its subdirectories.

    Disabled trace rules on Windows

    Enter a configuration code to disable specific trace rules by ID. Use this option only when working with Technical Support on the Trellix Thrive Portal

    Exclude process(es) by full path on Linux

    Enter the configuration code that can enable or disable trace rules by ID. We recommend that you enter information in this text box only when working with a Technical Support representative.

    The supported paths are:

    • Full path

    • FOLDERID_* paths

    • Paths with System environment variables. User environment variables are not supported.

    Wildcards are also supported.

    • <Folder>/* would include all processes within the folder and all its subdirectories.

    Disabled trace rules on Linux

    Enter the configuration code that can enable or disable trace rules by ID. We recommend that you enter information in this text box only when working with a Technical Support representative.

    Exclude file(s) on Linux

    Excludes specified files from being traced. Wildcards are not supported.

    Example — /var/spool/cron/testfile.txt

    Exclude folder(s) on Linux

    Excludes specified folders from being traced. Wildcards are not supported.

    Example — /var/spool/cron/testdir1;/var/spool/cron/testdir2/dir3

    Note

    Folder exclusions apply only to folders that exist on the endpoint when the policy is enforced. Exclusions do not apply to folders created later, even if they match the defined path.

    Exclude process(es) by full path on Mac

    Excludes a list of full paths (using folder id). If the path matches the one on a binary, the binary being executed will not be traced.

    The supported paths are:

    • Full path

    • FOLDERID_* paths

    • Paths with System environment variables. User environment variables are not supported.

    Wildcards are also supported.

    • <Folder>/* would include all processes within the folder and all its subdirectories.

    Disabled trace rules on Mac

    Enter configuration code that can enable or disable trace rules by ID. We recommend you to enter information in this text box only when working with a Technical Support representative.

Alerts

Option

Definition

Alerts Streamed to EDR Cloud

Streams Indicator of Compromise (IOC) detections to the Trellix EDR Cloud, along with other Trace data. You can disable this if you do not want IOC alerts sent to the cloud.

Process Tracker

Configure the Process Tracker server component on the HX server before enabling the Process Tracker client component in ePO.

Option

Definition

Enable Process Tracking on the host

Enables the tracking of process events on the host.

Logon Tracker

  • Configure the Logon Tracker server component on the HX server before enabling the Logon Tracker client component in ePO.

    Option

    Definition

    Enable Logon Tracker for hosts

    Enables or disables the Logon tracker module on endpoints. When enabled, the agent monitors and collects the logon and logoff events.

    Backfill events

    Instructs the agent to retrieve historical logon events from the endpoint's system logs upon initialization. This helps establish a baseline of logon activity that occurred before the module was activated.

    Logon timeout

    Specifies the duration in minutes after which an active logon session is considered timed out due to inactivity.

    Default: 1440 minutes

    Disable event enrichment

    Prevents the agent from adding supplementary contextual data (such as user details or group memberships) to the raw logon events. Disabling enrichment can reduce the size of the event data but provides less detailed information for analysis.

    Maximum number of events

    Defines the maximum number of logon events the agent stores in its local cache. This setting helps manage memory and resource consumption on the endpoint.

    Default: 5000000

  • Logon Tracker Exclusions — Exclusions allow you to filter which logon events are tracked. Separate multiple items with a semicolon (;).

    Option

    Definition

    Addresses

    Excludes logon events associated with specified IPv4 or IPv6 addresses.

    Hosts

    Excludes logon events from specified hostnames.

    Accounts

    Excludes logon events from specified user or system accounts.

    Categories

    Excludes specific logon categories.

    Status

    Excludes specific logon statuses.

  • Filtering Options

    Option

    Definition

    Filter Tunneled Logons

    Excludes logons that occur through a tunnel.