Cloud Endpoint server

Prev Next

Important

There are two versions of IAM. If the URL you use to access the IAM UI ends with fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends with trellix.com, see the Trellix IAM Guide for information regarding IAM.

Task

Information

Done

Verify that the customer ID on the Endpoint Security (HX) server matches the ID in the IAM Web UI.

  1. Run the show version command in the Endpoint Security (HX) CLI and locate the Customer ID field.

  2. Log into your Trellix Cloud Account and click My Settings > My Organization. Locate the Oracle Customer ID field on the Organization Settings page.

Central Management System-connected servers: Ensure that alerts and health statistics are sent directly to Trellix Helix and not through the Trellix Helix-enabled Central Management System appliance.

Run the show datastreaming helix command on each connected server and verify that the Helix data-streaming enabled field is yes.

Run the show helix health-stats status command on each connected server and verify that the Enabled field is yes.

Run the no fenet dti helix service override command on each connected server.

See Sending alerts and health stats directly from appliances.

Caution

Do not change the password for the permanent api_analyst user account on the cloud Endpoint Security (HX) server. Doing so could break the connection between the Endpoint Security (HX) server and Trellix Helix. If you need API connectivity between the Endpoint Security (HX) server and a third-party product, add another user account with the api_analyst role.