Integrating Trellix ePO with Trellix NDR is required to enrich security event data with critical endpoint asset information and to enable automated response actions, such as asset containment. Trellix NDR ingests details like asset name, Operating System (OS), and managed/unmanaged status from Trellix ePO to enhance its analysis capabilities.
Note
The configuration of integrated products is available only to users with an Enterprise or Core license.
From the main menu, click Integration Hub and then select the ePO.
Enter the Integration Name and Description for the Trellix ePO-On-Prem server.
Enter the name or IP address for configuring the Trellix ePO-On-Prem server.
Enter the HTTPS listening port of the Trellix ePO - On-prem server that will be used for communucating.
This option is enabled by default.
Enter the username and password to be used for connecting to the ePO server.
Select polling frequency to determine how often NDR fetches alerts from ePO.
Select the Enrichment checkbox. This enables Trellix NDR to query and retrieve endpoint asset details from Trellix ePO On-Prem for security event analysis. This option is enabled by default.
Select the Tasking checkbox. This enables Trellix NDR to communicate containment instructions back to Trellix ePO.
Enter the containment tag configured in Trellix ePO On-prem to orchestrate an asset containment security event.