Collecting device data for real-time search

Prev Next

Trellix EDR collects real-time data from devices running Trellix EDR clients. Trellix EDR collectors are components that run on managed devices, executed by search expressions.

Collectors specify what real-time data to collect from monitored devices, and how to report it back to Trellix EDR.

Note

Trellix EDR can collect real-time data from devices running on Active Response. The collectors that are not available in the MAR Client are ignored when used in a search expression and the result shows a column with empty values.

Certain Linux distributions might not have installed all the shell commands that Trellix EDR collectors and reactions use. If not installed by default, you need to install these shell commands manually.

Trellix EDR offers built-in collectors that come included by default as well as custom collectors that can be tailored to meet specific requirements. For more information on Built-in collectors and Custom collectors, see: