The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure data enrichment sources

Prev Next

Trellix ESM devices can receive information from data enrichment sources.

Note

Data enrichment files must be UTF8 encoded.

  1. From the Trellix ESM dashboard, click menu.png and select System Properties.

  2. Click Data Enrichment → Add.

    Tabs and fields on the Data Enrichment Wizard vary based on the enrichment type you select.

  3. On the Main tab, identify the source information.

  4. Source tab:

    • CIFS, NFS, FTP, SFTP, and SCP source types can only use external files for enrichment. The other source types require you to write a query for a database or regular expression.

    • Each entry must be on a separate line.

    • The file you pull for data enrichment must be formatted as LookupValue=EnrichmentValue. Single-column enrichment needs only lookup value entries. For two-column enrichment, separate lookup values from enrichment values with an equals symbol (=).

      For example, a file that uses IP address to host names:

      10.5.2.3=New York

      10.5.2.4=Houston

    • Type the source database driver.

    • Default authentication is None. If you select Basic, enter user name and password for the website if it requires you to log on.

    • For https websites, select Ignore Invalid Certificates to ignore invalid SSL certificates.

    • Type the Apache Hadoop Job Tracker Host address or IP address (not required). If blank, the system uses the Node Name Host.

    • Type the port where the Job Tracker Host listens (not required). If blank, the system uses the Node Name Host.

    • Default Method is GET. If you select POST, the post content or argument that might be required to navigate to the webpage with the content that you want to search on.

    • Select the directory for the files.

    • Type the Apache Hadoop Node Name Host address or IP address. Do not include protocol.

    • Type the port where the Node Name Host listens (not required). If blank, the system uses the Node Name Host.

    • Type the database path. If you select FTP in the Type field, the path is relative to your home directory. To specify an absolute path on the FTP server, insert an extra forward slash (/) at the beginning of the path. For example, //var/local/path.

    • Identify who can access the database. For LDAP, enter a fully qualified domain name with no spaces. For example, uid=bob,ou=Users,dc=example,dc=com or administrator@host.com.

  5. Parsing tab:

    • When you select HTTP/HTTPS as the source type, view the first 200 lines of the HTML source code for the URL entered in the URL field on the Source tab. It is only a preview of the website, but is enough for you to write a regular expression to match on.

      A Run Now or scheduled update of the data enrichment source includes all matches from your regular expression search. This feature supports RE2 syntax regular expressions, such as (\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}).

    • Typically, an Internet site has header code that you are not interested in searching. Specify how many lines from the top of the site you want to skip so that the search doesn't include header data.

    • Type what separates values you are interested in. This field has a default of \n, which indicates that a new line is the delimiter. The other most common delimiter is a comma.

    • Type a regular expression that removes any unwanted values from the results of your regular expression search.

    • (Required) Type the logic used to find a match and extract the values from the site. The most common use cases are to create an expression that matches on a list of known malicious IP addresses or MD5 sums listed on a site. If you provided two match groups in your regular expression, you can map the results of each regex match to Lookup Value or Enrichment Value.

    • Use a Lookup Value or Enrichment Value.

      • Use Lookup Value for events collected from Trellix ESM where you want to add more values. It maps to the Lookup Field on the Destination tab.

      • Use Enrichment Value for values that are enriched or inserted into the source events that match on the lookup value. It maps to the Enrichment Field on the Destination tab.

  6. On the Query tab, set up the query for Hadoop HBase (REST), Hive, LDAP, MSSQL, MySQL, Oracle, or PIG types.

  7. On the Scoring tab, set the score for each value that is returned on a single column query. Select the source and target field you want to score on, then click Run Query. Show the returned values and the numeric stepper that you can use to set the risk score for that value.

  8. On the Destination tab, identify the devices and the rule for field mapping for the devices that this data enrichment source populates.

  9. Click Finish, then click Write.

  10. Select the devices you want to enrich and create the field-mapping rule for those devices. Then click OK.

    Note

    If you select Use Static Value, you must enter the enrichment value.