When you initiate a Trellix Wise investigation request, the NDR automatically creates an Elasticsearch query to gather related telemetry.
The query uses a 10-minute time window. This window covers five minutes before and five minutes after the alert generation time. The NDR extracts the following parameters from the alert JSON to perform the search:
Source and destination IP addresses
Source and destination ports
Protocol
This search includes data consumed from connected NX, PX, and IPS appliances. After the NDR receives the events and flows from the search, it sends the gathered data to Trellix Wise for analysis.