This guide describes how to integrate the following Trellix products in a Trellix Helix environment.
Central Management System appliances.
Network Security appliances running Release 8.3.4 or later.
Network Security Evidence Collector Edition appliances running Release 9.1.1 or later.
Email Security — Server appliances running Release 8.4.3 or later.
Endpoint Security (HX) servers.
Note
Use the Cloud Connect page in the Trellix Helix Web UI (Configure > Cloud Connect) to integrate Email Security - Cloud and other data sources. See the Trellix Helix Product Guide for details.
When Trellix Helix mode is enabled on appliance, the following are automatically enabled:
Registration with the Registry and Discovery Service (RDS). This allows appliances to discover the Helix alert ingestion URI and the Helix Web UI URL so alerts can be sent to the Trellix Helix Web UI.
Streaming of alerts and health statistics to Trellix Helix.
Data streaming service to stream submission, email metadata, appliance metadata, sysinfo metadata, Windows event logs, Storytime metadata, and local signatures to Trellix Helix. Individual types of metadata streaming can be enabled or disabled as described in Configuring data streaming to Helix.
The HelixConnect Client. This allows you to manage Network Security and Email Security — Server appliances, take remediation actions on Network Security and Email Security — Server alerts, and take remediation and data extraction actions on Endpoint Security (HX) appliances, all from the Trellix Helix Web UI.
This guide shows how to re-enable, configure, and troubleshoot these features.
Both standalone appliances and appliances that are connected to a Central Management System appliance can be integrated with Trellix Helix. Trellix recommends that you configure appliances to send alerts and health statistics directly to Trellix Helix instead of through the Central Management System appliance. This is required if you want to take remediation actions or collect artifacts for alerts from the Trellix Helix Web UI.