xAgent on ePO

Prev Next

The xAgent Extension for ePO enables the integration of xAgent with the Trellix Agent and ePO ecosystem, allowing it to send alerts and process them, which are then displayed on the ePO threat events page.

You can install and deploy Agent (HX) using Trellix ePO - On-prem.

Important

The Forensics Bridge Module must be installed and enabled on the HX Server managing the Agent (HX) to ensure the alert forwarding capability to ePO is functional. For more information, see The Trellix Endpoint Forensics Bridge Product Guide.Install and configure Trellix Endpoint Forensics Bridge

The event or alert routing to Trellix ePO is only supported on Windows and macOS endpoints, as the Forensics Bridge module v1.1.3 does not support the Linux operating system.

  • Check in the Agent (HX) package.

    1. On Trellix ePO - On-prem, navigate to MenuSoftwareSoftware Catalog.

    2. On Software Catalog, navigate to Threat Analysis and select the Trellix Endpoint Forensics Bridge product. Then under Actions, click Check-in.

      Note

      You can also choose to select the appropriate Trellix Endpoint Security Agent (HX) package for Windows, Linux, or macOS endpoints.

      After you check in the Agent (HX) package, the extension is listed on the Extensions page and the installation packages are listed on the Main Repository page.