Verify the configuration

Prev Next

After saving the registered server, verify the configuration and confirm that trace data is being transmitted.

Verify DXL Broker publishing in the audit log

  1. In Trellix ePO, navigate to MenuReportingAudit Log.

    Tip

    The Audit Log table can be large. To find the events quickly, use the Quick Find bar to filter the log by searching for added or published.

  2. In the Audit Log table, look for the following events to confirm the server was added and the configuration was published:

    Action

    Details

    New Server

    Added Registered Server [Your-EDR Telemetry Store-Server-Name]

    Publish configuration to DXL Broker

    Successfully published configuration to DXL Broker

Verify the broker extension in the DXL Topology

Note

You can perform this verification only after the EDR Telemetry Store cluster is successfully deployed.

  1. In Trellix ePO, navigate to MenuConfigurationServer Settings.

  2. From the Setting Categories list, select DXL Topology .

  3. In the details pane, verify that your EDR Telemetry Store server is now listed under Broker Extensions. The following text is displayed by default:

    Broker Extensions: Forward events to [Your-EDR Telemetry Store-Server-Name]

  4. (Optional) If you have certain DXL Brokers that should not forward events, click Edit and clear the option.