The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring the Communications Broker Sender to send third-party logs to Helix

Prev Next

The Communications Broker Sender (Comm Broker) can send and receive third-party syslog and JSON formatted logs to Helix Enterprise for analysis.

Comm Broker functionality requires that Evidence Collector be enabled, so you must configure Evidence Collector with the Helix URL and certificate before starting Comm Broker. For details about how to enable Evidence Collector, see Enabling or disabling the Evidence Collector module using the Web UI on page 1 or Enabling or disabling the Evidence Collector module using the CLI.

Comm Broker can be configured with a transport protocol (UDP, TCP, or SSL) and a port (range 514 - 65355). You must configure the protocol and port before Comm Broker is enabled. Note that you should configure TCP as the protocol for better performance. For Helix Enterprise to analyze JSON data, you must configure the Comm Broker to send and receive third-party syslog and JSON formatted logs from different ports. For example, port 514 for syslog events and port 516 for JSON events.

Comm Broker can listen on the specified port and can directly access the IP address of the dedicated Helix Virtual Private Cloud (VPC) on a specific port.

Either Comm Broker or Evidence Collector can be disabled, but not both. The interactions of the possible Evidence Collector and Comm Broker configurations are listed below.

Configuration

Interaction

Default configuration

Both Evidence Collector and Comm Broker are disabled.

Only Evidence Collector is enabled

Evidence Collector is functional.

Only Comm Broker is enabled

Comm Broker is functional

Evidence Collector is already enabled when Comm Broker is enabled

The nxlog process is restarted and both Evidence Collector and Comm Broker are functional

Evidence Collector and Comm Broker are both enabled, and then Comm Broker is disabled

Comm Broker functionality stops and the nxlog process is restarted. Evidence Collector remains functional.

Evidence Collector and Comm Broker are both enabled, and then Evidence Collector is disabled

The nxlog process is stopped and the Comm Broker context remains enabled, but Evidence Collector functionality stops and Comm Broker remains functional.

Evidence Collector only is running and is then disabled

Evidence Collector functionality stops.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud

  • An active subscription to Helix

  • Configure a valid hostname for the VPC within an AWS endpoint (Helix Enterprise URL)

    Note

    To run the Evidence Collector module for Helix Enterprise, you must configure the Virtual Private Cloud (VPC) within an Amazon Web Services (AWS) endpoint on the Network Security appliance, see Configuring the VPC Within an AWS endpoint using the Web UI on page 1 or Configuring the VPC within an AWS endpoint using the CLI.

    You are not required to configure the VPC if you are sending only Layer 7 metadata events to the Splunk Enterprise server.