The Trellix appliance MVX Engine detects stealthy web, file, or email-based malware that uses malicious techniques to exploit client browsers, operating systems, emails and applications. Trellix detection of a malicious event generates alert details that can be sent from the appliance to an email, HTTP, SNMP, or rsyslog server or Security Information and Event Management (SIEM) platform in multiple formats, including CEF. This guide provides information about alert and event collection in the following formats:
Common Event Format (CEF)
Log Event Enhanced Format (LEEF)
Comma Separated Values (CSV)
Extensible Markup Language (XML)
JavaScript Object Notation (JSON)
NoteThis guide focuses on the formats that can be consumed by programs. Trellix also provides human-readable ASCII TEXT notifications that are not discussed in detail in this guide. |
The Trellix appliance Web UI Settings>Notifications menu provides the options for configuring alert notifications for each supported format to be sent to email, HTTP, SNMP, rsyslog or SIEM servers. The servers, in turn, must be configured to receive the notifications in the respective format(s).
When configuring a Trellix appliance to send alert notifications in CEF format, for example, an administrator must confirm that the rsyslog trap-sink server supports CEF. The CEF output is accessible for parsing only on the rsyslog server and cannot be viewed from the Trellix appliance CLI or Web UI.