This guide describes how to integrate the following Trellix products in a Helix Enterprise environment.
Central Management System appliances.
Network Security appliances running Release 8.3.4 or later.
Network Security Evidence Collector Edition appliances running Release 9.1.1 or later.
Email Security — Server appliances running Release 8.4.3 or later.
Endpoint Security (HX) servers.
Note
Use the Cloud Connect page in the Helix Enterprise Web UI (Configure > Cloud Connect) to integrate Email Security - Cloud and other data sources. See the Helix Enterprise Product Guide for details.
When Helix Enterprise mode is enabled on appliance, the following are automatically enabled:
Registration with the Registry and Discovery Service (RDS). This allows appliances to discover the Helix alert ingestion URI and the Helix Web UI URL so alerts can be sent to the Helix Enterprise Web UI.
Streaming of alerts and health statistics to Helix Enterprise.
Data streaming service to stream submission, email metadata, appliance metadata, sysinfo metadata, Windows event logs, Storytime metadata, and local signatures to Helix Enterprise. Individual types of metadata streaming can be enabled or disabled as described in Configuring data streaming to Helix.
The HelixConnect Client. This allows you to manage Network Security and Email Security — Server appliances, take remediation actions on Network Security and Email Security — Server alerts, and take remediation and data extraction actions on Endpoint Security (HX) appliances, all from the Helix Enterprise Web UI.
This guide shows how to re-enable, configure, and troubleshoot these features.
Both standalone appliances and appliances that are connected to a Central Management System appliance can be integrated with Helix Enterprise. Trellix recommends that you configure appliances to send alerts and health statistics directly to Helix Enterprise instead of through the Central Management System appliance. This is required if you want to take remediation actions or collect artifacts for alerts from the Helix Enterprise Web UI.