To enable the DXL fabric to send trace data to the EDR Telemetry Store virtual appliance, you must add the EDR Telemetry Store server information to Trellix ePO.
Prerequisites
Ensure the EDRF ePO extension is installed on Trellix ePO.
This process involves:
Configure the EDR Telemetry Store as a registered server in Trellix ePO.
The registered server configuration enables ePO to configure the DXL Brokers to establish a secure connection to the EDR Telemetry Store server using mTLS.
This configuration enables the end-to-end data flow:
TheEDRF Client delivers trace data using DXL over a TLS-encrypted communication to the DXL Broker.
The DXL Broker receives this trace data and securely transmits it using mTLS to the EDR Telemetry Store virtual appliance for storage and indexing.