Evidence collector

Prev Next

In the following example, the Central Management appliance and two IVX clusters are deployed in the same data center. One cluster analyzes objects submitted by a physical Network Security sensor that is deployed to monitor network traffic in the Seattle region. The other cluster analyzes objects submitted by two virtual sensors in the Portland region.

The physical Network Security sensor has Evidence Collector enabled. Evidence Collector collects network event logs generated by the sensor, and sends them to Helix for analysis. You can use the data to correlate Network Security alerts with a detailed event log analysis. (For information about enabling Evidence Collector, see the Network Security User Guide.)

In a Helix deployment, the sensor submits objects to the IVX cluster on one path, and sends the events to Helix on a different path.

image10.jpeg