The NDR appliance collects alerts from multiple Trellix appliances and displays them in the Web UI. The NDR appliance also generate alerts when matches are found between Mandiant Threat Intelligence IOCs and NDR metadata.
Note
Alert aggregation is off by default.
You can search alerts in the NDR Web UI. You can also view the alerts in the NDR Web UI Alerts Summary panel on the dashboard or on the Alerts page.
The NDR can receive alerts from the following Trellix appliances:
CM Series
HX Series
PX Series
NX Series
EX Series
Trellix IPS
Note
There are two ways to integrate with another Trellix appliance to receive alerts:
Alert Poll Service
Alert HTTP Listener
NX Series appliances uses HTTP Listener only.
Important
You must have a PX Series appliance deployed in your network in order to reconstruct PCAP for alerts generated from other Trellix appliances, including NX, EX, HX, and CM Series.
Important
The default configuration in NX is fenet proxy enabled. If fenet proxy is disabled in the NX, the fenotify preference ssl cipher list needs to be changed from Original to Compatible. When fenet proxy is disabled, the Original cipher list is not compatible with the fenotify preference ssl cipher list in NDR.