To send application-level messages to the Trellix Helix syslog server, you must add a domain-level syslog server to the DSM for each domain for which messages will be sent:
Log on to the DSM as an administrator. Choose either System Administrator or All for the administrator type.
Select to Domains > Switch Domains from the top menu.
.png)
Select the domain for which you want application-level messages sent to the syslog server.
Click the Switch to domain button.
Select Log > Syslog from the top menu.
Click Add.
Enter information in the following fields to match those set up on the Trellix Helix system:
Server Name (for example:
tap11206– should be the Trellix Helix system FQDN or IP address)Transport Protocol
Port Number
Message Format: Select CEF from the menu.
.png)
Click OK. Verify the details on the summary screen.
.png)