Skip to main content

CollectorsCloud Collectors Administration Guide

Configure the Trellix Endpoint Security Cloud Collector

Set up the Trellix Endpoint Security Cloud Collector to continuously ingest security alerts from hx/api/v3/alerts endpoint from Trellix APIs.

  1. Before you configure the Trellix Endpoint Security Cloud Collector, ensure that you complete the prerequisites.

  2. Log in to the New-Scale Security Operations Platform with your registered credentials as an administrator.

  3. Navigate to Collectors > Cloud Collectors.

  4. Click New Collector.

  5. Click Trellix Endpoint Security.

  6. Enter the following information for the cloud collector.

    Trellix_Configuration.png
    • NAME – Specify a name for the Cloud Collector instance.

    • URL – Enter the base URL of the API endpoint from which you want to collect alerts. For example, https://abcd.trt03.apps.abc.trellix.com.

    • USERNAME – Enter a valid user name for API authentication.

    • PASSWORD – Enter the password for the user name that you entered.

    • INGEST FROM – Select the time and date from which the collector must start ingesting events. If you leave this field blank and do not provide a threshold, all logs from past 24 hours are ingested.

  7. (Optional) SITE – Select an existing site or to create a new site with a unique ID, click manage your sites. Adding a site name helps you to ensure efficient management of environments with overlapping IP addresses.

    By entering a site name, you associate the logs with a specific independent site. A sitename metadata field is automatically added to all the events that are going to be ingested via this collector. For more information about Site Management, see Define a Unique Site Name.

  8. (Optional) TIMEZONE – Select a time zone applicable to you for accurate detections and event monitoring.

    By entering a time zone, you override the default log time zone. A timezone metadata field is automatically added to all events ingested through this collector.

    Timezone_sitename_site_management_1.png
  9. To confirm that the New-Scale Security Operations Platform communicates with the service, click Test Connection

  10. Click Install.

    AWS_S3_2.png

    A confirmation message informs you that the new Cloud Collector is created.