Configuring data streaming to Trellix Helix

Prev Next

The following types of data can be streamed to Trellix Helix. You can build custom dashboards in the Trellix Helix Web UI based on submission data, email metadata, appliance statistics, Endpoint Security (HX) syslog metadata and Windows event logs, and alerts.

  • Submission data with static and dynamic analysis details. In the Trellix Helix Web UI, you can search for a specific URL, file, or hash that was analyzed by an on-premises appliance. This provides more context about both malicious and nonmalicious submissions. (Available on on-premises Network Security and Email Security — Server appliances running in MVX integrated mode.)

  • Email metadata with details such as the verdict, attached objects, sender domain, analysis time, status, and so on. (Available on Email Security — Server appliances.)

  • Appliance statistics such as submission queue sizes; network bandwidth statistics (available on Network Security appliances); hold, deferred, bounced, maildrop, and active queue sizes (available on Email Security — Server appliances), and so on.

  • Endpoint Security (HX) sysinfo metadata with details such as agent status, host containment status, host operating system, and so on.

  • Endpoint Security (HX) Windows event logs for System, Application Experience, Security, AppLocker, PowerShell, Application, Windows Defender, Task Scheduler, Print Service, and Terminal Services events. (Available on Endpoint Security (HX) servers.)

  • Endpoint Security (HX) Storytime metadata such as the alert ID, chapter file, and details about what happened with the alert.

  • Health statistics such as the appliance uptime, disk status, license status, and services status.

  • Alerts that originate from Trellix Helix rules, customer rules, intel hits, Trellix Helix analytics, and so on.

  • Local signature (localsig) metadata for Trellix Helix to analyze and add to intelligence feeds (also known as observable feeds) to share with eligible connected appliances. (Available on Network Security and Email Security — Server appliances).

  • Network Security event logs that are correlated against Network Security-specific alerts in Trellix Helix to perform further forensic analysis. (Available on Network Security appliances.)

You can use the Trellix Helix Web UI to enable data streaming, except for Endpoint Security (HX) syslog metadata streaming and Windows event logs. The following table shows the methods you can use to enable each type of data streaming.

Data Type

Method(s)

Submission Data, Email Metadata, Appliance Statistics, Localsig Metadata

Helix Web UI. See Configuring data streaming to Helix using the Helix Web UI.

Appliance CLI. See Configuring data streaming to Helix using the appliance CLI.

Note

Global data streaming must be enabled before you can enable these data streaming types. Global data streaming is enabled by default when Trellix Helix mode is enabled on the appliance.

Localsig metadata streaming can be enabled automatically when you enable the appliance to receive observables shared by other appliances. For details, see the Trellix Helix Product Guide.

Endpoint Security (HX) sysinfo Metadata

Endpoint Security (HX) CLI. See Configuring data streaming to Helix using the appliance CLI.

Note

Sysinfo metadata streaming is enabled by default when Trellix Helix mode is enabled on the Endpoint Security (HX) appliance.

Endpoint Security (HX) Windows Event Logs

Event Streamer app. See the Event Streamer User Guide, available with the Event Streamer app in the Trellix Market.

Endpoint Security (HX) Storytime Metadata

Endpoint Security (HX) CLI. See Configuring data streaming to Helix using the appliance CLI.

Health Statistics, Alerts

Helix Web UI. See Configuring data streaming to Helix using the Helix Web UI.

Note

Health statistics and alert data streaming are enabled by default when Trellix Helix mode is enabled on the appliance. Appliances that are connected to a Central Management System appliance must send health statistics and alerts directly to Trellix Helix, as described in Sending alerts and health stats directly from appliances.

Network Security Event Logs

Helix Web UI. See Configuring data streaming to Helix using the Helix Web UI.

Network Security CLI or Web UI. See the Trellix Helix integration information in the Network Security User Guide. This information also shows how to create custom event filter rules.