The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Creating and sharing intelligence feeds

Prev Next

Trellix appliances generate local signatures (also known as observables) based on MVX analysis and DTI intelligence. Helix can collect local signatures from eligible appliances, match signature rules to create intelligence feeds (also known as observable feeds), and then share the feeds with all eligible connected appliances in your organization.

In a federated setup, feeds from eligible appliances can be shared across all organizations that have feed sharing enabled. Feed sharing can be enabled on child organizations even if it is disabled on the parent organization.

Signatures in Helix observable feeds expire 24 hours after they are created.

For a list of eligible appliances, see the "Software Requirements" section of the Helix Integration Guide.

The following Helix feeds are automatically created:

  • helix-<organization>-feed-md5-block-list

  • helix-<organization>-feed-url-block-list

Note

A Helix feed is treated as a third-party feed on eligible appliances. Helix feeds propagated to eligible Network Security appliances can be modified or deleted from the Settings > 3rd Party Feeds page in the Network Security Web UI or the Manage > Appliance Settings > 3rd Party Feeds page in the Helix Web UI. Any changes to a Helix feed will be overwritten when Helix propagates the feed to the appliance in the next cycle.

You can use the fireeye_localsig class to search Helix for streamed local signature metadata.

Feed sharing must be enabled for the feeds to be propagated from Helix so the signatures can be shared with appliances. Feed sharing can be enabled or disabled at various levels for granular control. Email notifications can be sent if feed propagation fails, as described in Configuring email notifications.Configuring email notifications

Note

An empty feed is propagated to all eligible appliances if the following are disabled: organization-level sharing, feed-level sharing, and appliance-level sharing. The empty feed changes the signature count on the 3rd Party Feeds page to zero.

A feed is removed from the 3rd Party Feeds page if federated feed sharing is subsequently disabled on the organization that propagated the feed to the appliance.

You can create custom feeds on individual appliances, as described in Custom feeds.Custom Feeds