Audits that cannot be imported

Prev Next

The following audit modules cannot be imported into a data acquisition script using the Endpoint Security (HX) Web UI because they involve processing that can badly affect your system performance or because they perform a function that has nothing to do with data acquisition. When attempts are made to import scripts that include these audits, errors occur.

For some of these audits, Trellix provides preconfigured data acquisition scripts that can be run for an individual host from the Hosts page. Associated preconfigured data acquisition scripts are listed in the table below. All of these audits can be requested using API bulk acquisitions.

Audit module

Supplied preconfigured

script (if any)

Legacy name

config

---

---

configuration

---

---

containment

---

---

diagnostic

---

---

disk‑acquisition

Raw Disk Script

w32disk‑acquisition

dissolve

---

---

driver‑memoryacquire

Driver Memory

w32driver‑memoryacquire

file‑acquisition‑api

---

w32apifile‑acquisition

file‑acquisition‑raw

---

w32rawfile‑acquisition

intel-key

---

---

iocload

---

---

iocmatch

---

---

log-audit

---

---

memory‑acquisition

Full Memory

w32memory‑acquisition

multifile‑acquisition‑api

---

w32multifileapi‑acquisition

multifile‑acquisition‑raw

---

w32multifileraw‑acquisition

plist-acquisition

---

---

processes‑memoryacquire

Process Memory

w32processes‑memoryacquire

reprovision

---

---

restart

---

---

upgrade

---

---

For more information about audit modules, see the

Endpoint Security (HX) Audit Reference Guide

.