The Streaming policy controls the flow of endpoint activity data for threat analysis. It allows you to configure the Trace plug-in to send security event information to the Trellix EDR cloud or an external S3 bucket.
Trace
Trace Scanning — Configures the Trace plug-in on managed devices to analyze system activity and identify the root cause of security incidents. For all exclusions, use a semicolon (;) to separate items; the maximum character limit is 3072.
Option
Definition
Enable Trace
Enables the Trace plug-in on the endpoints. This is enabled by default.
Log Level
Sets the level of detail for Trace log files (Debug, Trace, Info, Warning, Error). Each level includes its own information and all levels below it. Use the lowest log level possible, or disable this feature if you do not need log information.
Debug — Detailed debug information.
Trace — Contains most variable value dumps. This can be too verbose to debug problems on production systems.
Info — Logs messages that highlight the progress of the Trace plug-in.
Warning — Information about potentially harmful situations.
Error — Error events that might prevent the Trace plug-in from running.
The Trace log file is located at the following location:
Windows —
C:\ProgramData\Trellix\XClient\exts\plugin\UnifiedEdr\data\trace.logLinux —
/opt/Trellix/XClient/bin/xclient -g /tmp/xclient.logmac —
/Library/Application\ Support/Trellix/xclient/exts/plugin/UnifiedEdr/data/trace.log
Report internal reputation failures to Trellix ePO
Reports a threat event to ePO - SaaS if the Trace plug-in has internal connection issues. This is disabled by default.
Enable deep inspection of Windows API calls
Activates the agent's code injection detection plug-in to monitor and inspect Windows API usage for threat detection. This is enabled by default.
Enable ETW-TI inspection of Windows API calls
Enables the use of Event Tracing for Windows - Threat Intelligence (ETW-TI) to inspect Windows API calls for advanced threat detection. This is enabled by default.
Maximum size (MB) of the device storage that can be used by the Traces
Sets the size limit for the Trace database on the device. When this limit is reached, the oldest records are discarded.
Default: 80 MB
Range: 0–8192 MB
Interval to send trace events to Trellix EDR cloud
Specifies how often, in seconds, to send trace event notifications to the EDR cloud.
Default: 30 seconds
Range: 30–1800 seconds
Trace Destination — Collects detailed endpoint activity data and sends it to the cloud for in-depth analysis and threat investigation.
Note
This feature is enabled only for Windows endpoints.
Option
Definition
Send traces to Trellix EDR cloud
Sends traces collected on the endpoint to the Trellix EDR cloud. This is enabled by default.
Send traces to S3 bucket (Windows only)
Sends traces collected on the Windows endpoint to a compatible external cloud storage S3 bucket, such as Amazon Web Services (AWS) or Google Cloud Platform (GCP). This is disabled by default.
When enabled, add valid details in the fields displayed:
Access Key ID — Enter the access key ID for your S3 bucket..
S3 bucket Secret Access Key — Enter the secret access key associated with the Access Key ID.
S3 default Region Name — Enter the region where your S3 bucket is hosted (for example, us-east-1).
S3 bucket Name — Enter the exact name of your S3 bucket.
Interval (in seconds) to send trace events to S3 bucket — Specifies how often, in seconds, to send trace events.
Default: 30 seconds
Range: 10–1800 seconds
Specify (optional) S3 endpoint — Use this field to define a custom endpoint URL. This is required for certain S3-compatible services such as GCP Storage (for example, https://storage.googleapis.com). For standard AWS S3 buckets, this field can usually be left blank.
Verifying the Configuration — After you have entered your S3 bucket details, click the Verify configuration button to validate the settings. This check ensures that the EDR cloud can successfully connect to your bucket. You will receive one of the following messages:
Success: Indicates a valid connection. No issues were found with the bucket name, credentials, or permissions.
Warning: The connection is successful, but the provided credentials have excessive permissions. For this feature to function, the only required permission is the ability to create objects. This warning flags unnecessary permissions such as Get, List, or Delete. You can still save the configuration, but we recommend you limit the permissions to only what is required.
Exclusion — Configure exclusions to prevent the monitoring of trusted files, processes, or folders. This option is available when collectors are enabled and supports a character limit of 3072. Separate multiple items using a semicolon (;).
Option
Definition
Exclude process(es) by full path on Windows
Excludes specified processes from being traced.
The supported paths are:
Full paths
FOLDERID_*pathsPaths with System environment variables. User environment variables are not supported.
Wildcards
The path
<Folder>\*includes all processes in<Folder>and its subdirectories.
Disabled trace rules on Windows
Enter a configuration code to disable specific trace rules by ID. Use this option only when working with Technical Support on the Trellix Thrive Portal
Exclude process(es) by full path on Linux
Enter the configuration code that can enable or disable trace rules by ID. We recommend that you enter information in this text box only when working with a Technical Support representative.
The supported paths are:
Full path
FOLDERID_*pathsPaths with System environment variables. User environment variables are not supported.
Wildcards are also supported.
<Folder>/*would include all processes within the folder and all its subdirectories.
Disabled trace rules on Linux
Enter the configuration code that can enable or disable trace rules by ID. We recommend that you enter information in this text box only when working with a Technical Support representative.
Exclude file(s) on Linux
Excludes specified files from being traced. Wildcards are not supported.
Example —
/var/spool/cron/testfile.txtExclude folder(s) on Linux
Excludes specified folders from being traced. Wildcards are not supported.
Example —
/var/spool/cron/testdir1;/var/spool/cron/testdir2/dir3Note
Folder exclusions apply only to folders that exist on the endpoint when the policy is enforced. Exclusions do not apply to folders created later, even if they match the defined path.
Exclude process(es) by full path on Mac
Excludes a list of full paths (using folder id). If the path matches the one on a binary, the binary being executed will not be traced.
The supported paths are:
Full path
FOLDERID_*pathsPaths with System environment variables. User environment variables are not supported.
Wildcards are also supported.
<Folder>/*would include all processes within the folder and all its subdirectories.
Disabled trace rules on Mac
Enter configuration code that can enable or disable trace rules by ID. We recommend you to enter information in this text box only when working with a Technical Support representative.
Alerts
Option | Definition |
|---|---|
Alerts Streamed to EDR Cloud | Streams Indicator of Compromise (IOC) detections to the Trellix EDR Cloud, along with other Trace data. You can disable this if you do not want IOC alerts sent to the cloud. |
Process Tracker
Configure the Process Tracker server component on the HX server before enabling the Process Tracker client component in ePO.
Option | Definition |
|---|---|
Enable Process Tracking on the host | Enables the tracking of process events on the host. |
Logon Tracker
Configure the Logon Tracker server component on the HX server before enabling the Logon Tracker client component in ePO.
Option
Definition
Enable Logon Tracker for hosts
Enables or disables the Logon tracker module on endpoints. When enabled, the agent monitors and collects the logon and logoff events.
Backfill events
Instructs the agent to retrieve historical logon events from the endpoint's system logs upon initialization. This helps establish a baseline of logon activity that occurred before the module was activated.
Logon timeout
Specifies the duration in minutes after which an active logon session is considered timed out due to inactivity.
Default: 1440 minutes
Disable event enrichment
Prevents the agent from adding supplementary contextual data (such as user details or group memberships) to the raw logon events. Disabling enrichment can reduce the size of the event data but provides less detailed information for analysis.
Maximum number of events
Defines the maximum number of logon events the agent stores in its local cache. This setting helps manage memory and resource consumption on the endpoint.
Default: 5000000
Logon Tracker Exclusions — Exclusions allow you to filter which logon events are tracked. Separate multiple items with a semicolon (;).
Option
Definition
Addresses
Excludes logon events associated with specified IPv4 or IPv6 addresses.
Hosts
Excludes logon events from specified hostnames.
Accounts
Excludes logon events from specified user or system accounts.
Categories
Excludes specific logon categories.
Status
Excludes specific logon statuses.
Filtering Options
Option
Definition
Filter Tunneled Logons
Excludes logons that occur through a tunnel.