Use these instructions to configure Reservoir Labs R-Scope to output syslog data to Trellix Helix.
Prerequisite
You must have Administrator access.
To configure Reservoir Labs R-Scope for Trellix Helix and your environment:
Log in as admin and enter the following command:
logs export syslog dest add
Enter a unique identifier for the log destination.
Enter the IP address of the destination for your log.
Enter the port number.
Choose a transport protocol: enter 1 for TCP or 2 for UDP.
Press q to exit.