Log aggregation system configuration for Trellix Helix

Prev Next

If you have already implemented an enterprise log management system, you will likely be able to leverage those systems to send logs into Trellix Helix.

The following are required to ensure Trellix Helix effectively parses the log data from these systems:

  • Do not alter the original message.

  • Preserve the original source IP address (typically this spoofing requires UDP forwarding vs. TCP).

  • Preserve the original timestamp.

  • Preserve the original program name.

  • Preserve the original message format.

For examples of existing aggregations systems from which customers have successfully forwarded messages and logs, see Data Source Configuration.