The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring the Communications Broker Sender input module

Prev Next

You can configure the input module for the Communications Broker Sender (Comm Broker) by using the Network Security appliance Web UI or CLI:

The Communication Broker Sender (Comm Broker) module can send and receive third-party syslog and JSON formatted logs to Helix Enterprise for analysis.

For Helix Enterprise to analyze both syslog and JSON data at the same time, you must configure the Comm Broker to send and receive third-party logs using a different port, interface or protocol.

Note

The Comm Broker syslog and JSON input types cannot match. For example, the following are valid input modules for the Comm Broker:

  • commbroker input syslog interface ether1 proto tcp port 514

  • commbroker input json interface ether1 proto tcp port 516

  • commbroker input syslog interface ether1 proto tcp port 514

  • commbroker input json interface ether2 proto tcp port 514

When Comm Broker is already enabled and the appliance is upgraded, the nxlog process is restarted. Comm Broker will automatically restart using the syslog configuration input type.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud

  • An active subscription to Helix

  • Configure a valid hostname for the VPC within an AWS endpoint ( Helix Enterprise URL)

    Note

    To run the Evidence Collector module for Helix Enterprise, you must configure the Virtual Private Cloud (VPC) within an Amazon Web Services (AWS) endpoint on the Network Security appliance, see Configuring the VPC within an AWS endpoint using the Web UI or Configuring the VPC within an AWS endpoint using the CLI.

    You are not required to configure the VPC if you are sending only Layer 7 metadata events to the Splunk Enterprise server.