The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

System requirements

Prev Next

All Trellix SIEM appliances communicate via high-speed network infrastructure. Make sure your environment supports Trellix ESM.

These minimum requirements are for dedicated resources, not shared resources.

Supported VM platforms

  • Amazon Web Services (AWS)

  • Hyper-V VM

  • Linux KVM

  • Microsoft Azure

  • Oracle Cloud Infrastructure (OCI)

  • VMware ESXi

  • Xen Hypervisor

Network bandwidth and latency requirements

Trellix ESMs should be on a minimum of 1 Gbps network with the bandwidth of at least 500 Mbps for connections with the devices. For the remote Trellix ESMs that cross the WAN should have a bandwidth of at least 100 Mbps.

Note

The minimum requirements for individual devices should meet these requirements to make sure proper operation of the Trellix SIEM components.

The maximum network latency is 200 ms.

Note

The Heartbeat connection requires a network latency of 75 ms or better to prevent High Availability Receivers fail over and any issues. Any network latency issue requires Customer Support to fix the high availability receiver and improve the network.

VM RAM requirements

  • Trellix ESM - 16 GB

  • Trellix ESM - ELM - 16 GB

  • Trellix ELM - 4 GB

  • Trellix ERC - 8 GB

  • Trellix ESM - ACE - 32 GB (This also applies to combo boxes or Receivers that have a correlation engine)

    Note

    For the additional considerations when using correlation on Receivers or combo boxes, see Trellix Knowledge Base article KB96737.

  • Trellix DSB - 96 GB

Trellix Data Streaming Bus (Trellix DSB) VM requirements

  • 32 cores

  • 6-TB disk space

  • Ubuntu 18.04 Azure VMs

Third-party consumers

The Data Sharing and Message Forwarding features require an open port on the militarized network mapped to port 9092. This enables third-party consumers to access Data Streaming Bus public topics.

Required ports (all used ports)

All ports are TCP. All devices must allow two-way established connections.

  • 22 - TCP - all devices

  • 9092 - Kafka - Trellix Enterprise Security Manager - Event Receiver, Trellix ESM - ACE, Trellix Application Data Monitor, Trellix Data Streaming Bus

  • 1210 - Snowflex(server) gossip

  • 1211 - Snowflex - Trellix ESMs

  • 1212 - Snowman - Trellix ESMs

  • 1119 - EDB Secure - Trellix ESMs

  • 8103 - Snowclient/jdbc gossip - Trellix ESMs

  • 8104 - Snowclient/jdbc response - Trellix ESMs

  • 2181 - Databus management port (internal communications only)

Required ports for a non-clustered environment behind a firewall

For non-clustered Trellix ESM environments, whether the environment consists of combination appliances or discrete appliances, only these need to be open:

All ports are TCP. All devices must allow two-way established connections.

  • 22 - TCP - all devices

  • 9092 - Kafka - SIEM Collector, Trellix ESM - ACE, Trellix Application Data Monitor, Trellix DSB

Required ports for a clustered environment behind a firewall

Important

For environments where Trellix ESMs are clustered and might cross a firewall, additional ports must be open.

All ports are TCP. All devices must allow two-way established connections.

  • 1119 - EDB Secure - Trellix ESM-to-Trellix ESM communication.

  • 1210 - Snowflex(server) gossip

  • 1211 - Snowflex - Trellix ESMs

  • 1212 - Snowman - Trellix ESMs

  • 8103 - Snowclient/jdbc gossip - Trellix ESMs

  • 8104 - Snowclient/jdbc response - Trellix ESMs

  • 443 - Trellix ESM-to-Trellix ESM communication

GUID-26F06619-E1B1-47C0-913F-58D473B31F2E-low.png