Trellix Email Security - Server Edition configuration

Prev Next

Use these instructions to configure an Email Security — Server appliance to send notifications to Trellix Helix.

Prerequisites
  • The Email Security — Server appliance must have an established connection to the Internet.

  • You must have Admin access to the Email Security — Server appliance.

To configure rsyslog notifications:
  1. In the Email Security — Server Web UI, select the Settings tab.

    EX_Settings_Notifications.png
  2. Select Notifications on the side bar.

  3. Click the rsyslog column heading to display the Rsyslog Settings area in the Settings column.

  4. Select Common Event Format (CEF) in the Default format drop-down list.

    NX_rsyslog_settings.png
  5. Click Apply Settings.

    Note

    If you do not click Apply Settings, your changes will be lost.

  6. In the Rsyslog Server Listing area, enter the name or IP address of the Communications Broker or syslog-enabled Cloud Collector in the Name box and click Add Rsyslog Server.

    EX_rsyslog_server_listing.png
  7. To apply the rsyslog server listing changes, click Update.