Aggregating alerts from multiple appliances

Prev Next

The NDR appliance collects alerts from multiple Trellix appliances and displays them in the Web UI. The NDR appliance also generate alerts when matches are found between Mandiant Threat Intelligence IOCs and NDR metadata.

Note

Alert aggregation is off by default.

You can search alerts in the NDR Web UI. You can also view the alerts in the NDR Web UI Alerts Summary panel on the dashboard or on the Alerts page.

The NDR can receive alerts from the following Trellix appliances:

  • CM Series

  • HX Series

  • PX Series

  • NX Series

  • EX Series

  • Trellix IPS

Note

There are two ways to integrate with another Trellix appliance to receive alerts:

  • Alert Poll Service

  • Alert HTTP Listener

NX Series appliances uses HTTP Listener only.

Important

You must have a PX Series appliance deployed in your network in order to reconstruct PCAP for alerts generated from other Trellix appliances, including NX, EX, HX, and CM Series.

Important

The default configuration in NX is fenet proxy enabled. If fenet proxy is disabled in the NX, the fenotify preference ssl cipher list needs to be changed from Original to Compatible. When fenet proxy is disabled, the Original cipher list is not compatible with the fenotify preference ssl cipher list in NDR.