The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring Detection on Demand data streaming

Prev Next

Detection on Demand (DoD) event metadata can be streamed to Trellix Helix. This allows you to triage DoD alerts for detection and hunting directly in the Trellix Helix Web UI, and improves alert correlation in Trellix Helix. One regular or retroactive alert is sent to Trellix Helix for each malicious object.

Metadata for all DoD connectors is streamed to Trellix Helix after the Trellix Helix integration is enabled. The metadata is streamed as soon as a submission is complete or a retroactive alert is available in DoD. In the Trellix Helix Web UI, you can use the fireeye_dod class to search for DoD events that were streamed to Trellix Helix.

To enable DoD data streaming:

  1. Log in to the Detection on Demand Portal, available in the AWS Marketplace.

  2. Create a new authorization (API) key.

  3. Add a new Trellix Helix receiver.

    1. Provide a name and your Trellix Helix ID.

    2. Configure your notification and delivery preferences.

    3. Enable the receiver.

For more information, see the DoD Portal documentation here.