After saving the registered server, verify the configuration and confirm that trace data is being transmitted.
Verify DXL Broker publishing in the audit log
In Trellix ePO, navigate to Menu → Reporting → Audit Log.
Tip
The Audit Log table can be large. To find the events quickly, use the Quick Find bar to filter the log by searching for added or published.
In the Audit Log table, look for the following events to confirm the server was added and the configuration was published:
Action
Details
New Server
Added Registered Server [Your-EDR Telemetry Store-Server-Name]
Publish configuration to DXL Broker
Successfully published configuration to DXL Broker
Verify the broker extension in the DXL Topology
Note
You can perform this verification only after the EDR Telemetry Store cluster is successfully deployed.
In Trellix ePO, navigate to Menu → Configuration → Server Settings.
From the Setting Categories list, select DXL Topology .
In the details pane, verify that your EDR Telemetry Store server is now listed under Broker Extensions. The following text is displayed by default:
Broker Extensions: Forward events to [Your-EDR Telemetry Store-Server-Name]
(Optional) If you have certain DXL Brokers that should not forward events, click Edit and clear the option.