You can configure telemetry information in the Telemetry pop-up window that is displayed when you open the Manager for the first time, or by using the Telemetry page.
Perform the following steps to configure telemetry in the Manager:
Navigate to Manager → <Admin Domain Name> → Setup → Telemetry.
The Telemetry page is displayed.
Telemetry page.png)
Configure the following information categories (all of them are enabled in the Telemetry page by default). Select Yes to provide consent on the relevant information categories for which you prefer to send details to Trellix:
Alert Data Details - Select Alert Data Details for complete integration with Trellix endpoint reputation (that is, Trellix GTI endpoint reputation) services. This permits you to report, monitor, and take actions on endpoints/hosts involved in attacks based on their network reputation and/or country of origin. When the Alert Data Details option is selected, the following attributes are sent in real time for each alert seen and in batches every 3 hours to Trellix telemetry servers:
Application Name
Attack Name
Attack Time
Attacker DNS Name
Attacker IP Address
Attacker Country
Attacker OS
Attacker Port
Attacker Risk
Callback alert information
Category
Count
Detection Mechanism
Direction of Attack
For correlated alerts: Triggered component attacks and their connection logs
For heuristic attacks against web application servers: Threshold, confidence, weight, and the matched blocked strings
For Trellix Intelligent Sandbox attacks: File name, size, type, MD5 hash, UUID, and malware confidence
Malware Engine Results
Malware URL
Trellix IPS Attack ID
Protocol
Relevance (and method used to determine it)
Result
Signature ID
Sub-Category
Target DNS Name
Target IP Address
Target OS
Target Port
Target Risk
Type
URI
The following alert summary information is sent hourly to Trellix telemetry servers:
A count of each attack seen
The list of Trellix IPS attack IDs seen.
The following general setup information is sent daily to Trellix telemetry servers for the correct interpretation of the alert data:
Manager software version and active signature set version
You can also exclude data from specific endpoint IP addresses by using the Exclude IP address information for endpoints on this list option in the header. For more information, see Exclude IP address information for specific endpoints.
Note
No participation is required to enable Trellix File Reputation (that is, Trellix GTI File Reputation) service.
Alert Data Summary — Select Alert Data Summary for partial integration with Trellix endpoint reputation (that is, Trellix GTI endpoint reputation) services. This enables you to look up GTI for endpoints/hosts involved in attacks based on their network reputation and/or country details from the Attack Log. When the Alert Data Summary information category is selected, The following alert summary information is sent hourly to Trellix telemetry servers:
A count of each attack seen
The list of Trellix IPS attack IDs seen
The number of alerts whose relevance was determined by each available method
Top 10 (as per executable confidence) EIA attacks
The following general setup information is sent daily to Trellix telemetry servers for the correct interpretation of the alert data:
Manager software version and active signature set version
Note
No participation is required to enable Trellix File Reputation (that is, Trellix GTI File Reputation) service.
General Setup — When this information category is selected, the following general setup information is sent daily to Trellix telemetry servers:
Manager install type, software version, and active signature set version
Manager OS type, OS version, and VM type (if applicable)
Manager GUID, MDR GUID (as applicable), and Telemetry GUID
Is Central Manager in use
Is Manager Disaster Recovery (MDR) in use
OS type, OS version, and VM type (if applicable) of each device
Serial number, model, software, and hardware version of each device
Is each device part of an HA pair and/or stack
The number of monitor ports operating in inline, SPAN, and tap modes
The number of dedicated, CIDR, and VLAN interfaces defined
The number of administrative users, the custom roles in use, and the permissions in those roles
Callback Detector and GAM version for each active device
Interface name, protection category and assigned IPS, Malware and Inspection Options policy IDs
Is Suricata Snort Engine or Trellix IPS engine enabled on devices
Is tunneled traffic inspection enabled on devices
Is HTTP2 traffic inspection enabled on devices
Is Passive Device Profiling enabled on devices and if so, which technique is in use
Is integration with any of the Trellix products enabled on devices- Intelligent Sandbox, Intelligent Virtual Execution, Network Investigator, and Data Exchange Layer
Is Application Identification enabled on devices
Is any of the features or functionalities enabled on devices - Stateless scanning, jumbo frame parsing, stimulated blocking, L7 data collection, layer 2 bypass mode
The following data specific to IPS Manager and devices is necessary for Trellix business intelligence and automatically sent to Trellix telemetry servers everyday. This setup information is not user configurable:
IPS Manager Version
Device name, model, and software version
Feature Usage — When this information category is selected, the following feature usage information is sent daily to Trellix telemetry servers:
Are inbound MSRPC/SMB fragments being reassembled
Are outbound MSRPC/SMB fragments being reassembled
Callback Detectors status and version
Gateway Anti-Malware engine and DAT versions
Is ePO integration enabled
Is IPS alert notification enabled (SNMP, syslog, email, pager, script)
Is inbound GTI IP reputation lookup enabled
Is outbound GTI IP reputation lookup enabled
Is GTI IP reputation lookup used to enhance SmartBlocking decisions
Is inbound heuristic Web application server protection enabled
Is outbound heuristic Web application server protection enabled
Is inbound XFF header parsing enabled
Is outbound XFF header parsing enabled
Is advanced callback detection enabled, and are events sent to NTBA for further analysis
Is inbound chunked HTTP response traffic being decoded
Is outbound chunked HTTP response traffic being decoded
Is inbound HTML-encoded HTTP response traffic being decoded
Is outbound HTML-encoded HTTP response traffic being decoded
Is inbound base64-encoded SMTP traffic being decoded
Is outbound base64-encoded SMTP traffic being decoded
Is inbound GTI URL Reputation enabled
Is outbound GTI URL Reputation enabled
Is inbound Microsoft Office File Deep Inspection enabled
Is outbound Microsoft Office File Deep Inspection enabled
The L7 data collected (protocols and their fields)
The advanced malware policy definitions
The list of methods enabled for determining alert relevance
The number of default IPS policies in use
The number of custom IPS policies in use
The number of custom Trellix IPS-format attacks in use
The number of Snort rules in use
The number of ignore rules defined
The number of NS-series devices with IPS licenses assigned
The number of sub-interfaces in use
The number of device-pre firewall policies assigned
The number of port firewall policies assigned
The number of interface firewall policies assigned
The number of device-post firewall policies assigned
The number of IPS attack definitions whose default settings have been customized
The number of custom reports and their SQL queries
The number of interfaces with application identification enabled
The number of IPS devices with Trellix Intelligent Sandbox integration enabled and malware policies with Intelligent Sandbox analysis enabled
The number of NTBA devices with EIA integration enabled
The number of Virtual IPS sensors and Virtual IPS sensor licenses
The number of Interfaces using policy group
The number of custom policy group assigned
The number of default policy group assigned
The number of devices enabled inbound SSL decryption
The number of devices enabled inbound SSL decryption with Diffie-Hellman
Total number of devices with outbound SSL decryption enabled
Name, grant ID, license key, Sensor model, and allowance count associated with each proxy SSL decryption license
Total number of devices assigned a system license
The number of system licenses available and in use
Name, grant ID, license key, expiration, model and device associated with each system license
Block and alert only based CVE coverage for each of the IPS policies in use
Engine status and file types enabled for each of the Malware policies in use
Option status for each of the Inspection options policies in use
System Faults — With this information category selected, the following system fault information is sent hourly to Trellix telemetry servers:
Device Faults
Manager Faults
Note
Though these two events are represented separately, they are sent to Trellix GTI as a single event.
Trellix Virtual IPS Cluster Usage — The following data specific to vIPS clusters is sent daily to Trellix telemetry servers:
Name and grant ID associated with each Virtual IPS Sensor license
Virtual Sensor license compliance status
Total number of allowed virtual Sensors
Total number of Virtual Sensors currently in use with vIPS Clusters
Total number of virtual probes currently in use with vIPS Clusters
Maximum number of virtual probes used
Manager version
Note
The above information is necessary for Trellix business intelligence and sent automatically whenever at least one Virtual IPS cluster is defined.
Trellix License Usage — The following data specific to licenses and devices is sent daily to Trellix telemetry servers:
System License Details (License ID, Grant ID, Customer Name, expiry time)
SSL License Details (License ID, Grant ID, Customer Name, expiry time)
Virtual Sensor license details (License ID, Grant ID, Customer Name, expiry time)
Details of the Sensor for which license is applicable, its assigned license, and license status for each device
Note
The above information is necessary for Trellix business intelligence and is sent automatically.
In Alert Data Details Filter field, select the alert severity level(s) for which you want to send the alert details. Available severity levels are High, Medium, Low, and Informational.
Note
The Alert Data Details Filter is displayed only when you select Alert Data Details category.
In Technical Contact Information field, update the following fields to provide your contact information. The Manager collects the contact information only when you provide consent to send them via Send Contact Information? option.
First Name
Last Name
Street Address
Phone Number
Email Address
[Optional] To check whether communication to the GTI server is established, click Test Connection.
Click Save to finish the telemetry configuration task.