The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Level 7 collection on Trellix Intrusion Prevention System Manager

Prev Next

Layer 7 data populates the Trellix Intrusion Prevention System Manager database after the NSM event is written to its database. It doesn't come into the system as part of the event.

To pull Layer 7 information from the NSM, you can delay when the event is pulled so that Layer 7 data is included. This delay applies to all NSM events, not only the ones with associated Layer 7 data.

You can set this delay when performing three different actions related to the NSM:

  • Adding a Trellix NSM device to the console

  • Configuring an NSM device

  • Adding an NSM data source

Adding a Trellix Intrusion Prevention System Manager device

When adding the Trellix Intrusion Prevention System Manager device to Trellix ESM, select Enable Layer 7 Collection and set the delay on the Add Device Wizard.

Configuring a Trellix Intrusion Prevention System Manager device

After adding a Trellix Intrusion Prevention System Manager device to Trellix ESM, configure the connection settings for the device. You can select Enable Layer 7 Collection and set the delay.

Adding a Trellix Intrusion Prevention System Manager data source

To add a Trellix Intrusion Prevention System Manager data source to a Receiver, select Trellix in Data Source Vendor and Network Security Manager - SQL Pull (ASP) in Data Source Model. You can select Enable Layer 7 Collection and set the delay.