Configure Trellix EDR server settings using ePO - On-prem

Prev Next

You can configure Trellix EDR server settings using ePO - On-prem.

Make sure to add your Trellix EDR account credentials to MVISION Cloud Bridge and the connection between ePO - On-prem and Trellix EDR is successful.

  1. Log on to ePO - On-prem as an administrator.

  2. Select MenuConfiigurationServer SettingsTrellix EDR Settings, then click Edit.

  3. Enter Host (protocol://host), User, and Password for Intelligent Sandbox connection.

    Click Test Connection to verify the successful connection.

  4. Enter User and Password for SIEM Connection.

    Click Test Connection to verify the successful connection.

  5. Enable the Forward API service when integrating with SIEM, and using Trellix ePO extension as proxy in generating webhook URL from Manage integrations.

    The Forward API feature enables you to create an investigation directly on Trellix EDR from SIEM using the Trellix EDR extension.

    For details about creating webhook URLs, see Create webhooks to manage investigations.

  6. Enable the Debug option to check reason for the Trellix EDR cloud services, Intelligent Sandbox, and SIEM connection failure.

    For example, if the SIEM connection fails with status code TIMEOUT, StackTrace is displayed to debug the issue.

    The selected StackTrace option is temporarily enabled only until you click Save or Cancel.

  7. Enable Email notification to receive notification on losing connectivity for more than the configured time between Trellix EDR extension and Trellix EDR cloud.

    This feature requires the global email server to be configured on Trellix ePO - On-prem. Navigate to ConfigurationServer SettingsEmail Server for the configuration.

    Enter these details to configure this feature:

    • Timeout (in hours) — Enter the time period to receive email notification on losing connectivity. By default, the time period is set to 48 hours.

    • Number of reminders — Enter the number of email reminders. By default, it is set to 2.

    • Email recipients — Enter an email ID to receive notifications.

  8. Click Show advanced settings to display Endpoint Snapshots.

  9. Enable "ePO - On-prem to cloud" or "endpoints to cloud" to upload snapshots to Trellix cloud services.

Trellix EDR server settings are configured using ePO - On-prem.