Enables or disables the Evidence Collector module to collect logs generated by the Trellix Network Security appliance. When you enable the Evidence Collector module on the appliance, the appliance sends the network event logs to TAP in the AWS endpoint that you specified for further analysis. When you disable the Evidence Collector module on the appliance, the appliance does not send the network event logs to TAP in the AWS endpoint.
Note
TAP integration is not supported on the NX x3xx appliances and the NX 10000 appliance.
Caution
When the Evidence Collector module is enabled on the NX 4400 appliance models and above, peak throughput may be degraded by 10% to 15%.
When the Evidence Collector module is enabled on the NX 2500 appliance models and below, peak throughput may be degraded by 15% to 20%.
Syntax
[no] tapsender enable
Parameters
no
Use the no form of this command to disable the Evidence Collector module.
Example
The following example enables the Evidence Collector module.
hostname (config) # tapsender enable Enable tapsender Changes might take a few seconds to take effect. Use the CLI show tapsender status to check the status.
The following example disables the Evidence Collector module.
hostname (config) # no tapsender enable Disable tapsender
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 7.9