The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure Telemetry

Prev Next

The purpose of Telemetry is to facilitate you in providing helpful information to Trellix about your usage of Trellix IPS solution so that Trellix in turn optimizes your protection. You can configure telemetry information in Telemetry pop-up window that is displayed when you open the Manager for the first time, or by using the Telemetry page.

Perform the following steps to configure telemetry in the Manager:

  1. Navigate to Manager → <Admin Domain Name> → Setup → Telemetry.

    The Telemetry page is displayed.

    Telemetry page
    Telemetry page


  2. Configure the following information categories (all of them are enabled in the Telemetry page by default). Select Yes to provide consent on the relevant information categories for which you prefer to send details to Trellix:

    • Alert Data Details - Select Alert Data Details for complete integration with Trellix endpoint reputation (that is, Trellix GTI endpoint reputation) services. This permits you to report, monitor, and take actions on endpoints/hosts involved in attacks based on their network reputation and/or country of origin. When the Alert Data Details option is selected, the following attributes are sent in real time for each alert seen and in batches every 3 hours to Trellix telemetry servers:

      • Application Name

      • Attack Name

      • Attack Time

      • Attacker DNS Name

      • Attacker IP Address

      • Attacker Country

      • Attacker OS

      • Attacker Port

      • Attacker Risk

      • Callback alert information

      • Category

      • Count

      • Detection Mechanism

      • Direction of Attack

      • For correlated alerts: Triggered component attacks and their connection logs

      • For heuristic attacks against web application servers: Threshold, confidence, weight, and the matched blocked strings

      • For Trellix Intelligent Sandbox attacks: File name, size, type, MD5 hash, UUID, and malware confidence

      • Malware Engine Results

      • Malware URL

      • Trellix IPS Attack ID

      • Protocol

      • Relevance (and method used to determine it)

      • Result

      • Signature ID

      • Sub-Category

      • Target DNS Name

      • Target IP Address

      • Target OS

      • Target Port

      • Target Risk

      • Type

      • URI

      The following alert summary information is sent hourly to Trellix telemetry servers:

      • A count of each attack seen

      • The list of Trellix IPS attack IDs seen.

      The following general setup information is sent daily to Trellix telemetry servers for the correct interpretation of the alert data:

      • Manager software version and active signature set version

      You can also exclude data from specific endpoint IP addresses by using the Exclude IP address information for endpoints on this list option in the header. For more information, see Exclude IP address information for specific endpoints.

      Note

      No participation is required to enable Trellix File Reputation (that is, Trellix GTI File Reputation) service.

    • Alert Data Summary — Select Alert Data Summary for partial integration with Trellix endpoint reputation (that is, Trellix GTI endpoint reputation) services. This enables you to look up GTI for endpoints/hosts involved in attacks based on their network reputation and/or country details from the Attack Log. When the Alert Data Summary information category is selected, The following alert summary information is sent hourly to Trellix telemetry servers:

      • A count of each attack seen

      • The list of Trellix IPS attack IDs seen

      • The number of alerts whose relevance was determined by each available method

      • Top 10 (as per executable confidence) EIA attacks

      The following general setup information is sent daily to Trellix telemetry servers for the correct interpretation of the alert data:

      • Manager software version and active signature set version

      Note

      No participation is required to enable Trellix File Reputation (that is, Trellix GTI File Reputation) service.

    • General Setup — When this information category is selected, the following general setup information is sent daily to Trellix telemetry servers:

      • Manager install type, software version, and active signature set version

      • Manager OS type, OS version, and VM type (if applicable)

      • Manager GUID, MDR GUID (as applicable), and Telemetry GUID

      • Is Central Manager in use

      • Is Manager Disaster Recovery (MDR) in use

      • OS type, OS version, and VM type (if applicable) of each device

      • Serial number, model, software, and hardware version of each device

      • Is each device part of an HA pair and/or stack

      • The number of monitor ports operating in inline, SPAN, and tap modes

      • The number of dedicated, CIDR, and VLAN interfaces defined

      • The number of administrative users, the custom roles in use, and the permissions in those roles

      • Callback Detector and GAM version for each active device

      • Interface name, protection category and assigned IPS, Malware and Inspection Options policy IDs

      • Is Suricata Snort Engine or Trellix IPS engine enabled on devices

      • Is tunneled traffic inspection enabled on devices

      • Is HTTP2 traffic inspection enabled on devices

      • Is Passive Device Profiling enabled on devices and if so, which technique is in use

      • Is integration with any of the Trellix products enabled on devices- Intelligent Sandbox, Intelligent Virtual Execution, Network Investigator, and Data Exchange Layer

      • Is Application Identification enabled on devices

      • Is any of the features or functionalities enabled on devices - Stateless scanning, jumbo frame parsing, stimulated blocking, L7 data collection, layer 2 bypass mode

      The following data specific to IPS Manager and devices is necessary for Trellix business intelligence and automatically sent to Trellix telemetry servers everyday. This setup information is not user configurable:

      • IPS Manager Version

      • Device name, model, and software version

    • Feature Usage — When this information category is selected, the following feature usage information is sent daily to Trellix telemetry servers:

      • Are inbound MSRPC/SMB fragments being reassembled

      • Are outbound MSRPC/SMB fragments being reassembled

      • Callback Detectors status and version

      • Gateway Anti-Malware engine and DAT versions

      • Is ePO integration enabled

      • Is IPS alert notification enabled (SNMP, syslog, email, pager, script)

      • Is inbound GTI IP reputation lookup enabled

      • Is outbound GTI IP reputation lookup enabled

      • Is GTI IP reputation lookup used to enhance SmartBlocking decisions

      • Is inbound heuristic Web application server protection enabled

      • Is outbound heuristic Web application server protection enabled

      • Is inbound XFF header parsing enabled

      • Is outbound XFF header parsing enabled

      • Is advanced callback detection enabled, and are events sent to NTBA for further analysis

      • Is inbound chunked HTTP response traffic being decoded

      • Is outbound chunked HTTP response traffic being decoded

      • Is inbound HTML-encoded HTTP response traffic being decoded

      • Is outbound HTML-encoded HTTP response traffic being decoded

      • Is inbound base64-encoded SMTP traffic being decoded

      • Is outbound base64-encoded SMTP traffic being decoded

      • Is inbound GTI URL Reputation enabled

      • Is outbound GTI URL Reputation enabled

      • Is inbound Deep File Inspection enabled

      • Is outbound Deep File Inspection enabled

      • The L7 data collected (protocols and their fields)

      • The advanced malware policy definitions

      • The list of methods enabled for determining alert relevance

      • The number of default IPS policies in use

      • The number of custom IPS policies in use

      • The number of custom Trellix IPS-format attacks in use

      • The number of Snort rules in use

      • The number of ignore rules defined

      • The number of NS-series devices with IPS licenses assigned

      • The number of sub-interfaces in use

      • The number of device-pre firewall policies assigned

      • The number of port firewall policies assigned

      • The number of interface firewall policies assigned

      • The number of device-post firewall policies assigned

      • The number of IPS attack definitions whose default settings have been customized

      • The number of custom NextGen reports and their SQL queries

      • The number of interfaces with application identification enabled

      • The number of IPS devices with Trellix Intelligent Sandbox integration enabled and malware policies with Intelligent Sandbox analysis enabled

      • The number of NTBA devices with EIA integration enabled

      • The number of Virtual IPS sensors and Virtual IPS sensor licenses

      • The number of Interfaces using policy group

      • The number of custom policy group assigned

      • The number of default policy group assigned

      • The number of devices enabled inbound SSL decryption

      • The number of devices enabled inbound SSL decryption with Diffie-Hellman

      • Total number of devices with outbound SSL decryption enabled

      • Name, grant ID, license key, Sensor model, and allowance count associated with each proxy SSL decryption license

      • Total number of devices assigned a system license

      • The number of system licenses available and in use

      • Name, grant ID, license key, expiration, model and device associated with each system license

      • Block and alert only based CVE coverage for each of the IPS policies in use

      • Engine status and file types enabled for each of the Malware policies in use

      • Option status for each of the Inspection options policies in use

    • System Faults — With this information category selected, the following system fault information is sent hourly to Trellix telemetry servers:

      • Device Faults

      • Manager Faults

      Note

      Though these two events are represented separately, they are sent to Trellix GTI as a single event.

    • Trellix Virtual IPS Cluster Usage — The following data specific to vIPS clusters is sent daily to Trellix telemetry servers:

      • Name and grant ID associated with each Virtual IPS Sensor license

      • Virtual Sensor license compliance status

      • Total number of allowed virtual Sensors

      • Total number of Virtual Sensors currently in use with vIPS Clusters

      • Total number of virtual probes currently in use with vIPS Clusters

      • Maximum number of virtual probes used

      • Manager version

        Note

        The above information is necessary for Trellix business intelligence and sent automatically whenever at least one Virtual IPS cluster is defined.

    • Trellix License Usage — The following data specific to licenses and devices is sent daily to Trellix telemetry servers:

      • System License Details (License ID, Grant ID, Customer Name, expiry time)

      • SSL License Details (License ID, Grant ID, Customer Name, expiry time)

      • Virtual Sensor license details (License ID, Grant ID, Customer Name, expiry time)

      • Details of the Sensor for which license is applicable, its assigned license, and license status for each device

        Note

        The above information is necessary for Trellix business intelligence and is sent automatically.

  3. In Alert Data Details Filter field, select the alert severity level(s) for which you want to send the alert details. Available severity levels are High, Medium, Low, and Informational.

    Note

    The Alert Data Details Filter is displayed only when you select Alert Data Details category.

  4. In Technical Contact Information field, update the following fields to provide your contact information. The Manager collects the contact information only when you provide consent to send them via Send Contact Information? option.

    • First Name

    • Last Name

    • Street Address

    • Phone Number

    • Email Address

  5. [Optional] To check whether communication to the GTI server is established, click Test Connection.

  6. Click Save to finish the telemetry configuration task.