The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Adding or deleting the Communications Broker Sender input module using the CLI

Prev Next

Use the following CLI commands to add the input module or to delete the input module from the Comm Broker configuration.

To add an input module to the Communications Broker Sender configuration:

  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Specify the input format type for the Comm Broker module.

    • To specify the syslog format type:

      hostname (config) # commbroker input syslog
    • To specify the JSON format type:

      hostname (config) # commbroker input json
  3. Specify the management interface to receive incoming events sent over TCP, UDP, or SSL.

    Note

    The NX appliance can send data through Tapsender and Commbroker over IPv6 when an IPv6 address is configured on the ether1/either2 interface.

    • To specify the ether1 management interface:

      hostname (config) # commbroker input <formatType> interface ether1
    • To specify the ether2 management interface:

      hostname (config) # commbroker input <formatType> interface ether2
  4. Specify the type of protocol to receive the incoming syslog or JSON events.

    • To receive the incoming syslog or JSON events sent over TCP:

      hostname (config) # commbroker input <formatType> interface <interfaceName> proto tcp
    • To receive the incoming syslog or JSON events sent over UDP:

      hostname (config) # commbroker input <formatType> interface <interfaceName> proto udp
    • To receive the incoming syslog or JSON events sent over SSL:

      hostname (config) # commbroker input <formatType> interface <interfaceName> proto ssl
  5. Specify the port number that is used by Comm Broker to receive third-party syslog and JSON events.

    hostname (config) # commbroker input <formatType> interface <interfaceName> proto <protocolType> port <portNumber>

    where <portNumber> is the port number that is used to receive events. Valid values are integers ranging from 514 to 65535.

  6. Save your changes.

    hostname (config) # write memory
  7. Verify the configuration for the Comm Broker input modules.

    hostname (config) # show commbroker config

Example

This example shows how to add six input modules to the Comm Broker configuration.

hostname (config) # commbroker input json interface ether1 proto ssl port 517
hostname (config) # commbroker input json interface ether1 proto ssl port 518
hostname (config) # commbroker input json interface ether1 proto udp port 515
hostname (config) # commbroker input syslog interface ether1 proto ssl port 2322
hostname (config) # commbroker input syslog interface ether1 proto ssl port 4344
hostname (config) # commbroker input syslog interface ether1 proto tcp port 515
hostname (config) # show commbroker config

       input module:  syslog
           interface: ether1
           proto:     ssl
           port:      2322
           interface: ether1
           proto:     ssl
           port:      4344
           interface: ether1
           proto:     tcp
           port:      515

       input module:  json
           interface: ether1
           proto:     ssl
           port:      517
           interface: ether1
           proto:     ssl
           port:      518
           interface: ether1
           proto:     udp
           port:      515

To delete an input module from the Communications Broker Sender configuration:

  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Delete the input format type from the Comm Broker module.

    • To delete the syslog format type:

      hostname (config) # no commbroker input syslog
    • To delete the JSON format type:

      hostname (config) # no commbroker input json
  3. Delete the management interface from the Comm Broker input module.

    • To delete the ether1 management interface:

      hostname (config) # no commbroker input <formatType> interface ether1
    • To delete the ether2 management interface:

      hostname (config) # no commbroker input <formatType> interface ether2
  4. Delete the type of protocol from the Comm Broker input module.

    • To delete the TCP protocol:

      hostname (config) # no commbroker input <formatType> interface <interfaceName> proto tcp
    • To delete the UDP protocol:

      hostname (config) # no commbroker input <formatType> interface <interfaceName> proto udp
    • To delete the SSL protocol:

      hostname (config) # no commbroker input <formatType> interface <interfaceName> proto ssl
  5. Delete the port number from the Comm Broker input module.

    hostname (config) # commbroker input <formatType> interface <interfaceName> proto <protocolType> port <portNumber>

    where <portNumber> is the port number that is used to receive events. Valid values are integers ranging from 514 to 65535.

  6. Save your changes.

    hostname (config) # write memory
  7. Verify the configuration for the Comm Broker input modules.

    hostname (config) # show commbroker config

Example

The following example shows how to remove one syslog input format on the ether1 management interface using the TCP protocol on port 515 from the Comm Broker configuration.

hostname (config) # no commbroker input syslog interface ether1 proto tcp port 515
hostname (config) # show commbroker config

       input module:  syslog
           interface: ether1
           proto:     ssl
           port:      2322
           interface: ether1
           proto:     ssl
           port:      4344

       input module:  json
           interface: ether1
           proto:     ssl
           port:      517
           interface: ether1
           proto:     ssl
           port:      518
           interface: ether1
           proto:     udp
           port:      515