All Trellix SIEM appliances communicate via high-speed network infrastructure. Make sure your environment supports Trellix ESM.
These minimum requirements are for dedicated resources, not shared resources.
Supported VM platforms
Amazon Web Services (AWS)
Hyper-V VM
Linux KVM
Microsoft Azure
Oracle Cloud Infrastructure (OCI)
VMware ESXi
Xen Hypervisor
Network bandwidth and latency requirements
Trellix ESMs should be on a minimum of 1 Gbps network with the bandwidth of at least 500 Mbps for connections with the devices. For the remote Trellix ESMs that cross the WAN should have a bandwidth of at least 100 Mbps.
Note
The minimum requirements for individual devices should meet these requirements to make sure proper operation of the Trellix SIEM components.
The maximum network latency is 200 ms.
Note
The Heartbeat connection requires a network latency of 75 ms or better to prevent High Availability Receivers fail over and any issues. Any network latency issue requires Customer Support to fix the high availability receiver and improve the network.
VM RAM requirements
Trellix ESM - 16 GB
Trellix ESM - ELM - 16 GB
Trellix ELM - 4 GB
Trellix ERC - 8 GB
Trellix ESM - ACE - 32 GB (This also applies to combo boxes or Receivers that have a correlation engine)
Note
For the additional considerations when using correlation on Receivers or combo boxes, see Trellix Knowledge Base article KB96737.
Trellix DSB - 96 GB
Trellix Data Streaming Bus (Trellix DSB) VM requirements
32 cores
6-TB disk space
Ubuntu 18.04 Azure VMs
Third-party consumers
The Data Sharing and Message Forwarding features require an open port on the militarized network mapped to port 9092. This enables third-party consumers to access Data Streaming Bus public topics.
Required ports (all used ports)
All ports are TCP. All devices must allow two-way established connections.
22 - TCP - all devices
9092 - Kafka - Trellix Enterprise Security Manager - Event Receiver, Trellix ESM - ACE, Trellix Application Data Monitor, Trellix Data Streaming Bus
1210 - Snowflex(server) gossip
1211 - Snowflex - Trellix ESMs
1212 - Snowman - Trellix ESMs
1119 - EDB Secure - Trellix ESMs
8103 - Snowclient/jdbc gossip - Trellix ESMs
8104 - Snowclient/jdbc response - Trellix ESMs
2181 - Databus management port (internal communications only)
Required ports for a non-clustered environment behind a firewall
For non-clustered Trellix ESM environments, whether the environment consists of combination appliances or discrete appliances, only these need to be open:
All ports are TCP. All devices must allow two-way established connections.
22 - TCP - all devices
9092 - Kafka - SIEM Collector, Trellix ESM - ACE, Trellix Application Data Monitor, Trellix DSB
Required ports for a clustered environment behind a firewall
Important
For environments where Trellix ESMs are clustered and might cross a firewall, additional ports must be open.
All ports are TCP. All devices must allow two-way established connections.
1119 - EDB Secure - Trellix ESM-to-Trellix ESM communication.
1210 - Snowflex(server) gossip
1211 - Snowflex - Trellix ESMs
1212 - Snowman - Trellix ESMs
8103 - Snowclient/jdbc gossip - Trellix ESMs
8104 - Snowclient/jdbc response - Trellix ESMs
443 - Trellix ESM-to-Trellix ESM communication
![]() |
.png)