Network Security logs

Prev Next

The Evidence Collector module on the Network Security appliance is a log aggregator that collects logs generated by the appliance. The network event logs allow you to identify activity in your network before the Network Security-specific alert is triggered on the appliance.

When you enable the integration between Trellix Helix and the Network Security appliance, the Evidence Collector module on the Network Security appliance sends network event logs to Trellix Helix for further analysis.

The Communications Broker Sender (Comm Broker) can send and receive third-party syslog and JSON formatted logs to Trellix Helix for analysis. Comm Broker functionality requires that Evidence Collector be enabled. When you enable Trellix Helix mode on a Network Security appliance, the HelixConnect Client is also enabled. This allows the following to happen:

  • Evidence Collector is automatically configured with the Trellix Helix URL.

  • The bootstrap certificate that Evidence Collector and Comm Broker require is automatically downloaded and deployed.

Perform the integration steps in the following order:

  1. Enable Trellix Helix mode.

  2. Enable Evidence Collector.

  3. Start Comm Broker.

If you do not enable Trellix Helix mode first, you must manually download and deploy the bootstrap certificate. See the Network Security User Guide for information about enabling Evidence Collector, starting Comm Broker, and filtering out types of events you do not want to send to Trellix Helix. The Network Security User Guide also describes how Evidence Collector and Comm Broker interact.