The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable Layer 7 Data Collection for an interface or subinterface

Prev Next

You can enable Layer 7 Data Collection per interface or sub-interface. To optimize Sensor performance, you can also specify the protocols and the fields that are to be exported.

Task

  1. Click the Policy tab.
  2. From the Domain drop-down list, select the domain you want to inspect traffic.
  3. Navigate to Intrusion Prevention → Policy Manager.
  4. On the Interface tab, double-click the interface to enable the advanced traffic inspection.
    The <Device name/Interface> panel opens.
  5. In the Inspection Options section, select the policy from the Policy drop down list.
    To create a new policy, click the icon or double-click on the policy to edit an already assigned policy.
  6. The Properties page opens. Enter the Name and Description. Select the Visibility and click Next.
    The Inspection Options page opens.


  7. On the Traffic Inspection tab, under Miscellaneous, enable Layer 7 Data Collection in the required direction.
  8. Click Save in the Inspection Options page.
  9. To save the configuration changes, click Save in the <Device name/Interface> panel.
    You can manage layer 7 data collection options in the following path:
    1. Click the Devices tab.
    2. Select the domain from the Domain drop-down list.
    3. In the left pane, click the Devices tab.
    4. Select the device from the Device drop-down list.
    5. Navigate to Setup → Advanced → L7 Data Collection.
      The Layer 7 Data Collection page displays.
    6. Modify the required Layer 7 Data Collection options.

      Important

      Enabling Layer 7 Data Collection is per interface or sub-interface. However, the Layer 7 Data Collection options are device wide. That is, these changes are applied to all the interfaces and sub-interfaces of the corresponding device. Also, you must reboot the device for the changes to take effect. You can do a hitless or a full reboot.

      For NS-series Sensors, you must do a full reboot as hitless reboot is not supported when SSL decryption is enabled.



      Option Definition
      Percentage (%) of Flow Memory Re-Allocated to Collect Layer 7 Data The percentage of the maximum number of concurrent flows that capture Layer 7 data. The default value is 20%.

      Note

      For NS7500 and NS9500 Sensors above 10.1.5.116, the default value is set to 100%.

      For example, an M-1450 Sensor supports around 80,000 concurrent flows. So if you enable Layer 7 Data Collection with the default value of 20%, up to around 16,000 flows can capture Layer 7 data. Currently, if there are 20,000 flows passing through the Sensor, then only the first 16,000 flows are examined for Layer 7 data capture.

      You can click Edit to modify the percentage of flows that capture Layer 7 data. However, this will change the number of concurrent flows supported by the Sensor.

      Maximum Number of Concurrent TCP/UDP Flows Supported on this Device The maximum number of concurrent TCP/UDP flows supported by the Sensor. This capacity differs based on the Sensor model. Refer to Trellix Intrusion Prevention System Product Guide for the value for each model.
      Protocols/Fields To optimize Sensor performance, you can choose to enable it for certain fields of the required protocols.
      ftp Select Enable, Disable, or Customize to personalize your settings for the FTP protocol.

      Click to view the corresponding fields. The following options are available:

      • FTP Action
      • FTP Banner
      • FTP File Name
      • FTP Return Code
      • FTP User Name

      To disable a specific field, you must first select Customize.

      http Select Enable, Disable, or Customize to personalize your settings for the HTTP protocol.

      Click to view the corresponding fields. The following options are available:

      • HTTP CLSID
      • HTTP Host
      • HTTP Request Content Type
      • HTTP Request Filename
      • HTTP Request Method
      • HTTP Request Referrer
      • HTTP Request URL
      • HTTP Response Content Type
      • HTTP Return Code
      • HTTP Server Type
      • HTTP URI
      • HTTP User-Agent

      To disable a specific field, you must first select Customize.

      netbios-ss Select Enable, Disable, or Customize to personalize your settings for the NetBIOS protocol.

      Click to view the corresponding fields. The following options are available:

      • NetBIOS Action
      • NetBIOS File Name

      To disable a specific field, you must first select Customize.

      smtp Select Enable, Disable, or Customize to personalize your settings for the SMTP protocol.

      Click to view the corresponding fields. The following options are available:

      • SMTP Attachments
      • SMTP Banner
      • SMTP Recipients
      • SMTP Sender

      To disable a specific field, you must first select Customize.

      telnet Select Enable, Disable, or Customize to personalize your settings for the TELNET protocol.

      Click to view the corresponding fields. The following option is available:

      • TELNET User Name

      To disable, you must first select Customize.

      Save Applies the changes across the Sensor. You must do a hitless or full reboot for the changes to take effect.

      Note

      For NS-series Sensors, you must do a full reboot as hitless reboot is not supported when SSL decryption is enabled.