The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring forensic analysis integration using the Web UI

Prev Next

After you enable forensic analysis integration using the CLI, the Forensics tab is displayed on the Settings tab of the Web UI with a section on the Settings: Forensics page for each enabled integration.

NX_Forensics_scap.PNG

After the integration is configured, links to packet data are available in all alerts on the Alerts tab.

NX_ForensicsAlerts.scap.PNG

Prerequisites

To configure the integration with Solera Networks:

  1. In the Web UI, choose Settings > Forensics.

  2. In the Forensic Analysis Settings section:

    1. Enter the IP address of the Solera appliance in the Host box.

    2. Enter the port that listens for traffic from the Network Security appliance in the Port box.

  3. Click Update.

  4. To view packet capture (pcap) data:

    1. Click the Alerts tab and then click the Alerts sub-tab.

    2. Click the pcap link associated with the integration.

To configure the integration with RSA NetWitness:

  1. In the Web UI, choose Settings > Forensics.

  2. In the Netwitness Analysis Settings section, enter the NetWitness appliance base URL in the following format:

    https://<IP Address>/investigation/<Node ID>/navigate/query

    or

    http://<IP Address>/investigation/<Node ID>/navigate/query

    Note

    The URL depends on your specific NetWitness settings.

  3. Click Update.

  4. To view packet capture (pcap) data:

    1. Click the Alerts tab and then click the Alerts sub-tab.

    2. Click the pcap link associated with the integration.

To disable the integration, clear the Enable Netwitness Analysis checkbox in the Netwitness Analysis Settings section.

To configure the integration with a Packet Capture platform:

  1. In the Web UI, choose Settings > Forensics.

  2. In the Npulse Analysis Settings section, enter the PX Series appliance base URL in the following format:

    https://<IP Address>/i/searches.html

    or

    http://<IP Address>/i/searches.html

  3. Click Update.

  4. To view packet capture (pcap) data:

    1. Click the Alerts tab and then click the Alerts sub-tab.

    2. Click the pcap link associated with the integration.

To disable the integration, clear the Enable Npulse Analysis checkbox in the Npulse Analysis Settings section.