The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable Layer 7 Data Collection for an interface or subinterface

Prev Next

You can enable Layer 7 Data Collection per interface or sub-interface. To optimize Sensor performance, you can also specify the protocols and the fields that are to be exported.

  1. Click the Policy tab.

  2. From the Domain drop-down list, select the domain you want to inspect traffic.

  3. Navigate to Intrusion Prevention → Policy Manager.

  4. On the Interface tab, double-click the interface to enable the advanced traffic inspection.

    The <Device name/Interface> panel opens.

  5. In the Inspection Options section, select the policy from the Policy drop down list.

    To create a new policy, click the GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon or double-click on the policy to edit an already assigned policy.

  6. The Properties page opens. Enter the Name and Description. Select the Visibility and click Next.

    The Inspection Options page opens.

    Inspection_Options.png
  7. On the Traffic Inspection tab, under Miscellaneous, enable Layer 7 Data Collection in the required direction.

  8. Click Save in the Inspection Options page.

  9. To save the configuration changes, click Save in the <Device name/Interface> panel.

Perform the following steps to manage the layer 7 data collection options:

  1. Click the Devices tab and select the domain from the Domain drop-down list.

  2. In the left pane, click the Devices tab. Select the device from the Device drop-down list.

  3. Navigate to Setup → Advanced → L7 Data Collection.

    The Layer 7 Data Collection page is displayed.

  4. In the Layer 7 Data Collection page, there are two tabs: Flows and Protocols. Using these two tabs, you can configure the required Layer 7 Data Collection options.

    Important

    Enabling Layer 7 Data Collection is per interface or sub-interface. However, the Layer 7 Data Collection options are device wide. That is, these changes are applied to all the interfaces and sub-interfaces of the corresponding device.

    • You must do a hitless or full reboot for any changes made on the Flows tab to take effect. For NS-series Sensors, you must do a full reboot as hitless reboot is not supported when SSL decryption is enabled.

    • You must deploy the configuration changes to the required Sensors for the changes made on the Protocols tab to take effect.

    1. Flows tab

      Flows_tab_M7.png

      The Flows tab helps maintain the balance between flow memory percentage re-allocated for the collection of layer 7 data and number of concurrent TCP/UDP flows that a Sensor can support. The higher the percentage of flow memory re-allocated to collect layer 7 data, the higher is the probability that all layer 7 data will be collected, but the fewer number of concurrent TCP/UDP flows a Sensor would be able to support.

      The following configuration options are available in the grid view of the Flows tab:

      Option

      Definition

      Percentage (%) of Flow Memory Re-Allocated to Collect Layer 7 Data

      The percentage of the maximum number of concurrent flows that capture Layer 7 data. The default value is 20%.

      Note

      The default value is set to 100% for the following Sensor models:

      • For NS9600, NS7600, and NS3600 Sensors

      • For NS7500 and NS9500 Sensors above version 10.1.5.116

      For example, an NS7500 Sensor with 7.5Gbps throughput supports around 10,000,000 concurrent flows. So if you enable Layer 7 Data Collection with a value set to 30%, up to around 3,000,000 flows can capture Layer 7 data. Currently, if there are 5,000,000 flows passing through the Sensor, then only the first 3,000,000 flows are examined for Layer 7 data capture.

      You can modify the percentage of flows that capture Layer 7 data. However, this will change the number of concurrent flows supported by the Sensor. Click Save to save the changes.

      Maximum Number of Concurrent TCP/UDP Flows Supported on this Device

      The maximum number of concurrent TCP/UDP flows supported by the Sensor. This capacity differs based on the Sensor model.

      Refer to NS-series Sensor capacity by model number and Virtual IPS Sensor capacity by model number for the value for each model.

      Save

      Applies the changes across the Sensor. You must do a hitless or full reboot for the changes to take effect.

      Note

      For NS-series Sensors, you must do a full reboot as hitless reboot is not supported when SSL decryption is enabled.

    2. Protocols tab

      Protocols_tab_11_1M8.jpg

      Using the Protocols tab, you can choose to enable the collection of layer 7 data for certain fields of the required protocols and optimize Sensor performance.

      Use the expand_all_button.jpg button to view or customize the associated fields of all protocols listed on this tab. All fields are collapsed by default.

      The following configuration options are available on the Protocols tab:

      Option

      Definition

      netbios-ss

      Click Arrow.jpg to view or customize the corresponding fields for the NetBIOS and SMB protocols. All fields are enabled by default. To disable a specific field, deselect the associated check-box.

      Note

      To view or customize the SMBv1 and SMBv2 fields, you need to use Manager and Sensor that are running on 11.1 Update 8 release versions, and a compatible signature set with SMB related attack signatures.

      The following fields are available:

      • NetBIOS Action

      • NetBIOS File Name

      • Relevant fields of command SMB CMD NEGOTIATE in the request direction only

      • Relevant fields of the command SMB CMD TREE-CONNECT-ANDX in the request direction only

      • Relevant fields of the command SMB CMD Trans in the request direction only

      • Relevant fields of the command SMB CMD Trans2 in the request direction only

      • Relevant fields of the command SMB Header in both request and response directions

      • Relevant fields of the command SMBv2 Create in both request and response directions

      • Relevant fields of the command SMBv2 Find in the request direction only

      • Relevant fields of the command SMBv2 Header in both request and response directions

      • Relevant fields of the command SMBv2 IOCTL in the request direction only

      • Relevant fields of the command SMBv2 NEGOTIATE in both request and response directions

      • Relevant fields of the command SMBv2 Read in the request direction only

      • Relevant fields of the command SMBv2 Session Setup in both request and response directions

      • Relevant fields of the command SMBv2 Tree Connect in both request and response directions

      • Relevant fields of the command SMBv2 Write in the request direction only

      ftp

      Click Arrow.jpg to view or customize the corresponding fields for the FTP protocol. All fields are enabled by default. To disable a specific field, deselect the associated check-box.

      The following fields are available:

      • FTP Action

      • FTP Banner

      • FTP File Name

      • FTP Return Code

      • FTP User Name

      smtp

      Click Arrow.jpg to view or customize the corresponding fields for the SMTP protocol. All fields are enabled by default. To disable a specific field, deselect the associated check-box.

      The following fields are available:

      • SMTP Attachments

      • SMTP Banner

      • SMTP Recipients

      • SMTP Sender

      telnet

      Click Arrow.jpg to view or customize the corresponding field for the TELNET protocol. All fields are enabled by default. To disable a specific field, deselect the associated check-box.

      The following field is available:

      • TELNET User Name

      dcerpc

      Click Arrow.jpg to view or customize the corresponding field for the DCERPC protocol. All fields are enabled by default. To disable a specific field, deselect the associated check-box.

      Note

      DCERPC L7 data collection is supported over TCP only.

      Note

      To view or customize DCERPC fields, you need to use Manager and Sensor that are running on 11.1 Update 8 release versions, and a compatible signature set with DCERPC related attack signatures.

      The following fields are available:

      • Relevant fields of the command DCERPC Bind

      • Relevant fields of the DCERPC Header in both request and response directions

      • Relevant fields of the command DCERPC Request

      dns

      Click Arrow.jpg to view or customize the corresponding fields for the DNS protocol. All fields are enabled by default. To disable a specific field, deselect the associated check-box.

      Note

      To view or customize both DNS request and response fields, you need to use Manager and Sensor that are running on 11.1 Update 7 release versions, and a compatible signature set with DNS related attack signatures.

      The following DNS request and response based fields are available:

      • DNS OPCode

      • DNS RRName

      • DNS RRType

      • Relevant fields of the command DNS RSP Answer

      • Relevant fields of the command DNS RSP Answer Rdata

      • Relevant fields of the command DNS RSP Authority

      • Relevant fields of the command DNS RSP Authority Rdata

      • DNS RSP Header Flags

      • DNS TXID

      • DNS Type

      http

      Click Arrow.jpg to view or customize the corresponding fields for the HTTP protocol. All fields are enabled by default. To disable a specific field, deselect the associated check-box.

      The following fields are available:

      • HTTP CLSID

      • HTTP Host

      • HTTP Request Content Type

      • HTTP Request Filename

      • HTTP Request Method

      • HTTP Request Referrer

      • HTTP Request URL

      • HTTP Response Content Type

      • HTTP Return Code

      • HTTP Server Type

      • HTTP URI

      • HTTP User-Agent

      • HTTP2 STREAM ID

      • HTTP2 Settings Enable Push (Client)

      • HTTP2/3 HTTP VERSION

      ssl

      Click Arrow.jpg to view or customize the corresponding fields for the SSL protocol. All fields are enabled by default. To disable a specific field, deselect the associated check-box.

      The following fields are available:

      • SSL Certificate Common Name

      • SSL Server Name Indication

      Save

      Applies the changes across the Sensor. You must deploy the configuration changes to the required Sensors for the changes to take effect. For more information, see Deploy pending changes to a device.