Trellix ESM Syslog Connector
Configure Trellix Syslog event forwarding
Trellix Enterprise Security Manager (ESM) is the foundation of the Trellix security information and event management solution (SIEM). You can create a connector to forward all data types to Trellix Enterprise Security Manager.
You must configure your Trellix SIEM Solution to receive Syslog data sources.
- In BeyondInsight, go to Configuration > General > Connectors.
- From the Connectors pane, click Create New Connector.
- Enter a name for the connector.
- Select Trellix Syslog Event Forwarding from the Connector Type list.
- Click Create Connector.
- Leave Active (yes) enabled.
- Select an optional syslog facility from the list.
- Provide the required details for the available output pipelines for the Trellix Syslog data source:
- Select the protocol: TCP, TCP-SSL, or UDP.
- Enter Host Name and Port.
- Select an output format: NewLine Delimited, Tab Delimited, or Comma Delimited.
- Expand Event Filters, and then select the events you want to forward.
- Click Test Connector to send a test event message.
- Click Create Connector.
Note
For more information, see the Trellix documentation for configuring a Syslog data source to SIEM solution.
Updated 5 days ago