Enabling data streaming on appliances

Prev Next

Use the Data Streaming page in the Helix Enterprise Web UI to enable or disable the streaming of various types of data from an on-premises Trellix appliance to Helix Enterprise. The following illustration is from a connected Email Security — Server appliance.

Note

The data streaming settings that are available depend on the system image running on the appliance. For the minimum system image for each setting, see the "Software Requirements" section of the Helix Integration Guide.

The following types of data can be streamed:

  • Stats Metadata—Appliance statistics, such as the number of received, queued, and running submissions.

  • Health—Health statistics, such as the appliance uptime, disk status, license status, and services status.

  • Alerts—Event data for alerts generated on appliances.

  • Submission Metadata—Static and dynamic analysis details from URLs, files, or hashes analyzed by the local MVX engine in the appliance. This provides more context about both malicious and non-malicious submissions.

    Note

    Submission metadata streaming is only available on appliances running in MVX integrated mode.

  • LocalSig Stream—Local signatures generated by appliances based on MVX analysis and DTI intelligence.

  • TapSender Metadata (Network Security appliance)—Network event logs sent from the Evidence Collector module for further analysis.

  • Email Metadata (Email Security — Server appliance)—Metadata such as the sender, recipient, attached object details, and delivery status.

Note

Endpoint Security (HX) Windows event log data can also be streamed to Helix Enterprise. This data is streamed through the Event Streamer Module, which is downloaded, installed, and configured from the Endpoint Security (HX) Web UI. For details, see the Event Streamer User Guide, which is available with the Event Streamer Module app in the Trellix Market.

To enable or disable data streaming:
  1. From the main menu, select Manage > Appliance Settings.

  2. Select the appliance from the drop-down list.

  3. Click the Data Streaming tab on the sidebar.

  4. Select or clear the checkbox for each type of data for which you want to enable or disable streaming.

  5. Click Update.

Note

You can also use the appliance CLI to enable or disable streaming for each type of data. To synchronize the Data Streaming page with the CLI configuration, click the refresh button at the top right corner.