The following types of data can be streamed to Trellix Helix. You can build custom dashboards in the Trellix Helix Web UI based on submission data, email metadata, appliance statistics, Endpoint Security (HX) syslog metadata and Windows event logs, and alerts.
Submission data with static and dynamic analysis details. In the Trellix Helix Web UI, you can search for a specific URL, file, or hash that was analyzed by an on-premises appliance. This provides more context about both malicious and nonmalicious submissions. (Available on on-premises Network Security and Email Security — Server appliances running in MVX integrated mode.)
Email metadata with details such as the verdict, attached objects, sender domain, analysis time, status, and so on. (Available on Email Security — Server appliances.)
Appliance statistics such as submission queue sizes; network bandwidth statistics (available on Network Security appliances); hold, deferred, bounced, maildrop, and active queue sizes (available on Email Security — Server appliances), and so on.
Endpoint Security (HX) sysinfo metadata with details such as agent status, host containment status, host operating system, and so on.
Endpoint Security (HX) Windows event logs for System, Application Experience, Security, AppLocker, PowerShell, Application, Windows Defender, Task Scheduler, Print Service, and Terminal Services events. (Available on Endpoint Security (HX) servers.)
Endpoint Security (HX) Storytime metadata such as the alert ID, chapter file, and details about what happened with the alert.
Health statistics such as the appliance uptime, disk status, license status, and services status.
Alerts that originate from Trellix Helix rules, customer rules, intel hits, Trellix Helix analytics, and so on.
Local signature (localsig) metadata for Trellix Helix to analyze and add to intelligence feeds (also known as observable feeds) to share with eligible connected appliances. (Available on Network Security and Email Security — Server appliances).
Network Security event logs that are correlated against Network Security-specific alerts in Trellix Helix to perform further forensic analysis. (Available on Network Security appliances.)
You can use the Trellix Helix Web UI to enable data streaming, except for Endpoint Security (HX) syslog metadata streaming and Windows event logs. The following table shows the methods you can use to enable each type of data streaming.
Data Type | Method(s) |
|---|---|
Submission Data, Email Metadata, Appliance Statistics, Localsig Metadata | Helix Web UI. See Configuring data streaming to Helix using the Helix Web UI. Appliance CLI. See Configuring data streaming to Helix using the appliance CLI.
|
Endpoint Security (HX) sysinfo Metadata | Endpoint Security (HX) CLI. See Configuring data streaming to Helix using the appliance CLI.
|
Endpoint Security (HX) Windows Event Logs | Event Streamer app. See the Event Streamer User Guide, available with the Event Streamer app in the Trellix Market. |
Endpoint Security (HX) Storytime Metadata | Endpoint Security (HX) CLI. See Configuring data streaming to Helix using the appliance CLI. |
Health Statistics, Alerts | Helix Web UI. See Configuring data streaming to Helix using the Helix Web UI.
|
Network Security Event Logs | Helix Web UI. See Configuring data streaming to Helix using the Helix Web UI. Network Security CLI or Web UI. See the Trellix Helix integration information in the Network Security User Guide. This information also shows how to create custom event filter rules. |