Trellix Endpoint Security (via Codeless Connector Framework)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Connectors Index


Attribute Value
Connector ID TrellixConnector
Publisher Microsoft
Used in Solutions Trellix
Collection Method CCF
Connector Definition Files Trellix_DataConnectorDefinition.json
DCR Definition Files Trellix_DCR.json
CCF Configuration Trellix_PollingConfig.json
CCF Capabilities OAuth2, Paging
Microsoft Learn View on Learn

The Trellix Endpoint Security data connector enables you to ingest security events from Trellix ePO (ePolicy Orchestrator) into Microsoft Sentinel. This connector uses OAuth2 client credentials authentication and automatically handles pagination to collect comprehensive endpoint security data including threat detections, analyzer information, source and target system details, and threat response actions.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
TrellixEvents_CL ? ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. API Configuration

Configure your Trellix ePO API connection.

Authentication

Provide your API key for authentication. This will be sent in the x-api-key header.

ℹ️ The API key will be securely stored and used for authentication with the Trellix ePO API.

2. Authentication Configuration

Configure OAuth2 authentication credentials.

OAuth2 Configuration

Configure OAuth2 client credentials for API access. Read about the Trellix API authorization model at https://developer.manage.trellix.com/public/mvision/docs/umam

ℹ️ OAuth2 authentication provides secure access to your API endpoints.

3. Enable Connector

Activate the Trellix Endpoint Security connector

Connector Activation

Review your configuration and enable the connector to start collecting security events.

Post-Connection

After connecting, monitor the connector status in the Data connectors page. Data should begin appearing within 5-10 minutes.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Connectors Index